CVE-2025-36633

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.
References
Link Resource
https://www.tenable.com/security/tns-2025-11 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:tenable:nessus_agent:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Oct 2025, 16:00

Type Values Removed Values Added
First Time Microsoft windows
Microsoft
Tenable
Tenable nessus Agent
References () https://www.tenable.com/security/tns-2025-11 - () https://www.tenable.com/security/tns-2025-11 - Vendor Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:tenable:nessus_agent:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) En versiones de Tenable Agent anteriores a 10.8.5 en un host Windows, se descubrió que un usuario no administrativo podía eliminar arbitrariamente archivos del sistema local con privilegios de SYSTEM, lo que potencialmente podía provocar una escalada de privilegios locales.

13 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-13 15:15

Updated : 2025-10-23 16:00


NVD link : CVE-2025-36633

Mitre link : CVE-2025-36633

CVE.ORG link : CVE-2025-36633


JSON object : View

Products Affected

tenable

  • nessus_agent

microsoft

  • windows
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo