CVE-2025-36640
8.8Tenable · Nessus Agent
A privilege escalation vulnerability exists in the Tenable Nessus Agent Tray App for Windows during installation or uninstallation processes.
Executive summary
A vulnerability in the Tenable Nessus Agent for Windows allows local authenticated users to escalate privileges, potentially resulting in a full system compromise.
Vulnerability
This flaw, classified as Improper Privilege Management (CWE-269), occurs within the Tray App component during installation or uninstallation. A local user with low privileges can exploit this to achieve elevated system control.
Business impact
Successful exploitation allows an attacker to gain elevated privileges on a host machine, which could lead to unauthorized system access, data exfiltration, or the deployment of persistent malware. Given the CVSS score of 8.8, this vulnerability represents a high risk to organizational security, particularly for environments where Nessus Agents are deployed across sensitive infrastructure.
Remediation
Immediate Action: Update all Windows-based Nessus Agents to version 11.0.3 or 10.9.3 as specified in the official Tenable security advisory.
Proactive Monitoring: Review system logs for unusual process execution or unauthorized installation/uninstallation activity involving the Nessus Agent Tray App.
Compensating Controls: Restrict local user permissions on systems where Nessus Agents are installed and limit the ability of non-administrative users to trigger software installation or removal tasks.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Organizations should prioritize the deployment of the patched Nessus Agent versions across all Windows endpoints. Because this vulnerability facilitates privilege escalation, it is imperative to ensure that administrative controls are robust and that patch management cycles are strictly enforced to mitigate the risk of local exploitation.
More Tenable CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
- Fix documented version 10.9.3 per CVE record