PT-2025-22809 · Tenable · Tenable Network Monitor

Will Dormann

·

Published

2025-05-23

·

Updated

2025-06-03

·

CVE-2025-24916

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenable Network Monitor versions prior to 6.5.1
Description The issue arises when Tenable Network Monitor is installed to a non-default location on a Windows host. In such cases, versions prior to 6.5.1 did not enforce secure permissions for sub-directories, potentially allowing for local privilege escalation if users had not secured the directories in the non-default installation location.
Recommendations For versions prior to 6.5.1, update to version 6.5.1 or later to resolve the issue. As a temporary workaround, consider manually securing the sub-directories in the non-default installation location to prevent local privilege escalation.

Fix

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-24916

Affected Products

Tenable Network Monitor