In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27853 In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
Fixes

Solution

Tenable has released Nessus 10.8.5 and Nessus 10.9.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/nessus


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Wed, 02 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Jul 2025 23:30:00 +0000

Type Values Removed Values Added
Description In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
Title Local Privilege Escalation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2025-07-02T13:24:24.991Z

Reserved: 2025-04-15T21:50:46.277Z

Link: CVE-2025-36630

cve-icon Vulnrichment

Updated: 2025-07-02T13:05:30.775Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-02T00:15:22.543

Modified: 2025-10-15T19:52:46.780

Link: CVE-2025-36630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-06T22:16:24Z