CVE-2025-36631

Published Jun 13, 2025

Last updated 12 hours ago

CVSS high 8.4
Tenable Agent

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-36631 is a vulnerability found in Tenable Agent versions prior to 10.8.5 on Windows. It stems from an improper privilege management issue. A non-administrative user could exploit this vulnerability to overwrite arbitrary local system files with log content while operating at SYSTEM privilege. This vulnerability could allow a local, non-administrative user to gain elevated privileges on the system. Tenable has released version 10.8.5 of the agent to address this and other vulnerabilities.

Description
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
Source
vulnreport@tenable.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.4
Impact score
5.8
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Severity
HIGH

Weaknesses

vulnreport@tenable.com
CWE-269

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4

References

Sources include official advisories and independent security research.