Tenable Nessus Windows Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability exists in Tenable Nessus versions prior to 10.8.4 when installed in a non-default location on Windows. These versions did not apply secure permissions to sub-directories, potentially allowing users to escalate privileges if they had not manually secured the directories in the non-default installation path.

Impact

Exploitation of this vulnerability could lead to unauthorized local privilege escalation on the affected Windows system.

Remediation

Users can upgrade to Tenable Nessus version 10.8.4, which addresses this vulnerability. The installation files are available from the Tenable Downloads Portal.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.