← Vulnerability feed

Vulnerability record · CVE-2025-36633 · published 13 June 2025

CVE-2025-36633: Tenable nessus agent improper privilege management vulnerability

Tenable · Nessus Agent

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.

7.8 CVSS 3.1 High EPSS 0.18% · top 92.9% CWE-269 · Improper privilege management
7.8CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-36633 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-15265Tenable nessus agent path traversal vulnerabilityA path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intende…EPSS 0.56%7.8CVE-2025-36632Tenable nessus agent incorrect default permissions vulnerabilityIn Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.EPSS 0.20%7.8CVE-2025-36631Tenable nessus agent improper privilege management vulnerabilityIn Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files…EPSS 0.17%7.8CVE-2020-5793Tenable nessus vulnerabilityA vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local att…EPSS 0.40%7.4CVE-2026-33694Tenable nessus link following vulnerabilityThis vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condit…EPSS 0.20%7.4CVE-2021-3450Openssl improper certificate validation vulnerabilityThe X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Sta…EPSS 18%7.3CVE-2023-5847Tenable nessus improper privilege management vulnerabilityUnder certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Wind…EPSS 0.22%6.7CVE-2021-20118Tenable nessus agent vulnerabilityNessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrato…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2025-36633), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.