PT-2025-12421 · Tenable · Nessus Agent

Will Dormann

·

Published

2025-03-21

·

Updated

2025-03-23

·

CVE-2025-24915

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nessus Agent versions prior to 10.8.3
Description The issue arises when Nessus Agent is installed to a non-default location on a Windows host. In such cases, Nessus Agent did not enforce secure permissions for sub-directories, which could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
Recommendations For Nessus Agent versions prior to 10.8.3, update to version 10.8.3 or later to resolve the issue. As a temporary workaround, consider manually securing the directories in the non-default installation location to prevent local privilege escalation.

Fix

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-24915

Affected Products

Nessus Agent