Impact
This vulnerability is a command injection flaw in the Active Directory Events Listener component of Tenable Identity Exposure (SaaS). An authenticated user with low privileges can inject and execute arbitrary operating‑system commands with SYSTEM rights on the PDCe, effectively granting remote code execution to the attacker. The flaw is classified as CWE-78.
Affected Systems
Affected deployments are Tenable’s Identity Exposure SaaS offering, specifically the Active Directory Events Listener. No specific version numbers are supplied by the CNA, so all releases prior to the documented fix are potentially impacted.
Risk and Exploitability
The CVSS base score of 9.4 indicates critical severity. Because the EPSS score is not available, the current exploit probability is uncertain, but the high CVSS and the fact that the flaw allows execution with SYSTEM privileges warrant immediate remediation. The vulnerability requires valid authentication but only a low‑privileged user, reducing the initial barrier and making it likely that attackers with legitimate credentials can exploit it. The flaw is not listed in the CISA KEV catalog as of the latest data.
OpenCVE Enrichment