Source: Ministry of education information & communication security contingency platform
Publication Number | TACERT-ANA-2025062001063131 | Publication Time | 2025/06/20 13:04 |
Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/06/20 13:04 |
Impact Level | Low | ||
[Subject] [Vulnerability Alert] Critical Security Vulnerability in Tenable Nessus Agent (CVE-2025-36633) |
|||
[Content] Forwarded from TWCERTCC-200-202506-00000015 Tenable provides the widely deployed vulnerability scanning tool Nessus, along with the world’s first exposure management platform for securing digital assets across any environment. Recently, Tenable disclosed a critical security vulnerability (CVE-2025-36633, CVSS: 8.8). In affected versions of Nessus Agent on Windows systems prior to version 10.8.5, non-administrator users may be able to delete arbitrary system files using SYSTEM-level privileges, leading to local privilege escalation. Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
[Affected Platform] Tenable Agent versions earlier than 10.8.5 |
|||
[Recommended Actions] Please update to Tenable Agent version 10.8.5 |
|||
[Reference] https://www.twcert.org.tw/tw/cp-169-10191-409d1-1.html |