Impact
A local privilege escalation flaw in Tenable Security Center allows an attacker who can write to a particular configuration file to execute arbitrary code with elevated privileges, leading to full system compromise. The weakness is an OS command injection vulnerability (CWE‑78), enabling the attacker to run arbitrary commands on the host. No additional user action is required beyond possessing write access to the file.
Affected Systems
The flaw affects Tenable, Inc. Security Center. The specific versions impacted are not enumerated, but any installation that predates the Sec. Center 6.9.0 fix is vulnerable. The patch addresses all affected releases by tightening file permissions and securing command handling.
Risk and Exploitability
The CVSS score of 8.5 indicates severe risk. Because the exploit requires local write access to a configuration file, the attack vector is local and depends on attacker privileges. EPSS is not available, but the lack of a KEV listing suggests no known public exploits at this time, still the high impact warrants caution. An attacker who already has the necessary file write rights can achieve remote code execution without further interaction.
OpenCVE Enrichment