HomeSecurityUpdates for serious vulnerabilities in Tenable Nessus

Updates on serious vulnerabilities in Tenable Nessus

Tenable has released security updates for three high-severity vulnerabilities in Nessus Agent for Windows, which could be exploited to execute file and code operations with elevated privileges.

See also: Acer Control Center vulnerability allows malicious code execution

Tenable Nessus vulnerabilities

The first vulnerability, codenamed CVE-2025-36631 (CVSS score 8.4), allows users with non-administrative accounts to overwrite arbitrary local system files with log file content, gaining System privileges. The second vulnerability, CVE-2025-36632 (CVSS 7.8), allows arbitrary code execution with System privileges by non-administrative users. Finally, CVE-2025-36633 (CVSS 8.8) allows arbitrary local system files to be deleted, also with System privileges, by users without administrative privileges.

Successful exploitation of these vulnerabilities could lead to elevation of privilege on the affected computer, according to Tenable.

See also: Critical vulnerability exposes Mitel MiCollab platform to hacking

The three vulnerabilities affect Nessus Agent versions 10.8.4 and earlier and were patched with the release of version 10.8.5 , which is available through Tenable's download portal .

Updates on serious vulnerabilities in Tenable Nessus

The company does not report any incidents of these vulnerabilities being exploited in real attacks, but recommends that users update their installations as soon as possible.

Tenable Nessus agents are lightweight applications that are installed locally to collect information from systems. They are used to identify security vulnerabilities, compliance issues, and other types of information.

In early January, Tenable disabled versions 10.8.0 and 10.8.1 of its Nessus agents after they were found to be failing after a differential plugin update, but not due to a vulnerability. The company said at the time that it was not a security incident and that no customers were negatively impacted.

See also: Hackers target users through SimpleHelp vulnerability

Based on the above, it is clear that the security of Nessus Agents is a critical element for the protection of information systems, especially when it comes to tools that operate with elevated rights (System privileges). The vulnerabilities fixed with version 10.8.5 show how important it is to regularly patch software, even in auxiliary tools that may be considered "low risk".

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS