CVE-2025-36631

Published Jun 13, 2025

Last updated 2 months ago

CVSS high 8.4
Tenable Agent

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-36631 is a vulnerability found in Tenable Agent versions prior to 10.8.5 on Windows. It stems from an improper privilege management issue. A non-administrative user could exploit this vulnerability to overwrite arbitrary local system files with log content while operating at SYSTEM privilege. This vulnerability could allow a local, non-administrative user to gain elevated privileges on the system. Tenable has released version 10.8.5 of the agent to address this and other vulnerabilities.

Description
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
Source
vulnreport@tenable.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.4
Impact score
5.8
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Severity
HIGH

Weaknesses

vulnreport@tenable.com
CWE-269

Social media

Hype score
Not currently trending
  1. ⚠️ Vulnerabilidades de Nessus corregidas ❗CVE-2025-36633 ❗CVE-2025-36631 ❗CVE-2025-36632 ➡️Más info: https://t.co/rYGFxXUF9g https://t.co/AJopyil0Hv

    @CERTpy

    20 Jun 2025

    117 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Tenable patches three critical vulnerabilities in Nessus Agent for Windows (CVE-2025-36631/32/33), enabling privilege escalation, file deletion, and arbitrary code execution. Update to version 10.8.5 now 🔒🖥️ #Vulnerability #SecurityUpdate #US https://t.co/gxieOoQYBc

    @TweetThreatNews

    16 Jun 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Tenable Agent for Windowsに深刻な権限昇格の脆弱性。CVE-2025-36631~36633は、非管理者のユーザーがSYSTEM権限でそれぞれ任ファイルの上書き、任意コードの実行、任ファイルの削除を行えるもの。バージョン10.8.5で修正

    @__kokumoto

    15 Jun 2025

    1238 Impressions

    2 Retweets

    10 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  4. [CVE-2025-36631: HIGH] In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.#cve,CVE-2025-36631,#cybersecurity https://t.co/jXI6c2RZMt https://t.c

    @CveFindCom

    13 Jun 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-36631 In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content… https://t.co/DAke0ALbEF

    @CVEnew

    13 Jun 2025

    452 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.