AI description
CVE-2025-36630 is a vulnerability found in Tenable Nessus versions prior to 10.8.5 on Windows. It allows a non-administrative user to overwrite arbitrary local system files with log content at SYSTEM privilege. This improper privilege management in Nessus can be exploited through the Nessus logging mechanism. Successful exploitation of CVE-2025-36630 could lead to attackers tampering with critical system files, potentially causing system instability, privilege escalation, or denial of service. To address this vulnerability, Tenable has released Nessus versions 10.8.5 and 10.9.0.
- Description
- In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
- Source
- vulnreport@tenable.com
- NVD status
- Analyzed
- Products
- nessus
CVSS 3.1
- Type
- Primary
- Base score
- 7.1
- Impact score
- 5.2
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Severity
- HIGH
- vulnreport@tenable.com
- CWE-269
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
- CVE-2025-36630 (CVSS:8.4, HIGH) is Awaiting Analysis. In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit..https://t.co/5I7wGzK2tf #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre - @cracbot - 7 Jul 2025 - 7 Impressions - 0 Retweets - 0 Likes - 1 Bookmark - 0 Replies - 0 Quotes 
- Windows向けTenable Nessus Agentに権限昇格の脆弱性。CVE-2025-36630は非管理者ユーザが、SYSTEM権限で任意のローカルシステムファイルをログの中身で上書きすることが可能なもの。修正版提供済み。 https://t.co/zsKaH2XriS - @__kokumoto - 2 Jul 2025 - 1807 Impressions - 1 Retweet - 16 Likes - 5 Bookmarks - 0 Replies - 1 Quote 
- ⚠️ Nessus for Windows Vulnerabilities Enables Privilege Escalation Attacks Read more: https://t.co/xAZBZEEpnW The security flaws, affecting all Nessus versions prior to 10.8.5, include a critical Windows-specific vulnerability (CVE-2025-36630) that allows unauthorized file - @The_Cyber_News - 2 Jul 2025 - 1197 Impressions - 13 Retweets - 22 Likes - 7 Bookmarks - 1 Reply - 0 Quotes 
- Tenable社のWindows版Nessusに深刻な脆弱性(CVE-2025-36630)が発見された。これは非管理者ユーザーがSYSTEM権限で任意のシステムファイルを上書きできる可能性があるもので、特にマルチユーザー環境でのリスクが高 - @yousukezan - 2 Jul 2025 - 2611 Impressions - 4 Retweets - 22 Likes - 6 Bookmarks - 0 Replies - 0 Quotes 
- CVE-2025-36630 In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log conten… https://t.co/drH1fIvQW3 - @CVEnew - 1 Jul 2025 - 761 Impressions - 0 Retweets - 0 Likes - 0 Bookmarks - 0 Replies - 0 Quotes 
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "E18D5743-273C-46E4-8DC2-9505675EC484",
            "versionEndExcluding": "10.8.5"
          }
        ],
        "operator": "OR"
      },
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
            "vulnerable": false,
            "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
          }
        ],
        "operator": "OR"
      }
    ],
    "operator": "AND"
  }
]