AI description
CVE-2025-36630 is a vulnerability found in Tenable Nessus versions prior to 10.8.5 on Windows. It allows a non-administrative user to overwrite arbitrary local system files with log content at SYSTEM privilege. This improper privilege management in Nessus can be exploited through the Nessus logging mechanism. Successful exploitation of CVE-2025-36630 could lead to attackers tampering with critical system files, potentially causing system instability, privilege escalation, or denial of service. To address this vulnerability, Tenable has released Nessus versions 10.8.5 and 10.9.0.
- Description
- In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
- Source
- vulnreport@tenable.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8.4
- Impact score
- 5.8
- Exploitability score
- 2
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
- Severity
- HIGH
- vulnreport@tenable.com
- CWE-269
- Hype score
- Not currently trending
Windows向けTenable Nessus Agentに権限昇格の脆弱性。CVE-2025-36630は非管理者ユーザが、SYSTEM権限で任意のローカルシステムファイルをログの中身で上書きすることが可能なもの。修正版提供済み。 https://t.co/zsKaH2XriS
@__kokumoto
2 Jul 2025
1807 Impressions
1 Retweet
16 Likes
5 Bookmarks
0 Replies
1 Quote
⚠️ Nessus for Windows Vulnerabilities Enables Privilege Escalation Attacks Read more: https://t.co/xAZBZEEpnW The security flaws, affecting all Nessus versions prior to 10.8.5, include a critical Windows-specific vulnerability (CVE-2025-36630) that allows unauthorized file
@The_Cyber_News
2 Jul 2025
1197 Impressions
13 Retweets
22 Likes
7 Bookmarks
1 Reply
0 Quotes
Tenable社のWindows版Nessusに深刻な脆弱性(CVE-2025-36630)が発見された。これは非管理者ユーザーがSYSTEM権限で任意のシステムファイルを上書きできる可能性があるもので、特にマルチユーザー環境でのリスクが高
@yousukezan
2 Jul 2025
2611 Impressions
4 Retweets
22 Likes
6 Bookmarks
0 Replies
0 Quotes
CVE-2025-36630 In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log conten… https://t.co/drH1fIvQW3
@CVEnew
1 Jul 2025
761 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes