PT-2025-27580 · Tenable · Tenable Nessus

Published

2025-06-30

·

Updated

2025-08-08

·

CVE-2025-36630

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Tenable Nessus versions prior to 10.8.5
Description: A security issue was discovered where a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege on a Windows host.
Recommendations: For versions prior to 10.8.5, update to version 10.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to system files to minimize the risk of exploitation.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-11610
CVE-2025-36630

Affected Products

Tenable Nessus