A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-26950 A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-04T08:39:26.035Z

Reserved: 2020-01-06T00:00:00

Link: CVE-2020-5793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-05T20:15:17.270

Modified: 2024-11-21T05:34:36.493

Link: CVE-2020-5793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.