CVE-2025-36630

Published Jul 2, 2025

Last updated 14 days ago

CVSS high 8.4
Tenable Nessus

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-36630 is a vulnerability found in Tenable Nessus versions prior to 10.8.5 on Windows. It allows a non-administrative user to overwrite arbitrary local system files with log content at SYSTEM privilege. This improper privilege management in Nessus can be exploited through the Nessus logging mechanism. Successful exploitation of CVE-2025-36630 could lead to attackers tampering with critical system files, potentially causing system instability, privilege escalation, or denial of service. To address this vulnerability, Tenable has released Nessus versions 10.8.5 and 10.9.0.

Description
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
Source
vulnreport@tenable.com
NVD status
Analyzed
Products
nessus

Risk scores

CVSS 3.1

Type
Primary
Base score
7.1
Impact score
5.2
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Severity
HIGH

Weaknesses

vulnreport@tenable.com
CWE-269
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. CVE-2025-36630 (CVSS:8.4, HIGH) is Awaiting Analysis. In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit..https://t.co/5I7wGzK2tf #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    7 Jul 2025

    7 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  2. Windows向けTenable Nessus Agentに権限昇格の脆弱性。CVE-2025-36630は非管理者ユーザが、SYSTEM権限で任意のローカルシステムファイルをログの中身で上書きすることが可能なもの。修正版提供済み。 https://t.co/zsKaH2XriS

    @__kokumoto

    2 Jul 2025

    1807 Impressions

    1 Retweet

    16 Likes

    5 Bookmarks

    0 Replies

    1 Quote

  3. ⚠️ Nessus for Windows Vulnerabilities Enables Privilege Escalation Attacks Read more: https://t.co/xAZBZEEpnW The security flaws, affecting all Nessus versions prior to 10.8.5, include a critical Windows-specific vulnerability (CVE-2025-36630) that allows unauthorized file

    @The_Cyber_News

    2 Jul 2025

    1197 Impressions

    13 Retweets

    22 Likes

    7 Bookmarks

    1 Reply

    0 Quotes

  4. Tenable社のWindows版Nessusに深刻な脆弱性(CVE-2025-36630)が発見された。これは非管理者ユーザーがSYSTEM権限で任意のシステムファイルを上書きできる可能性があるもので、特にマルチユーザー環境でのリスクが高

    @yousukezan

    2 Jul 2025

    2611 Impressions

    4 Retweets

    22 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-36630 In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log conten… https://t.co/drH1fIvQW3

    @CVEnew

    1 Jul 2025

    761 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.