CVE-2025-24915
EUVD-2025-724621.03.2025, 15:15
When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tenable | nessus_agent | 𝑥 < 10.8.3 | CNA |
Common Weakness Enumeration