Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

High-Severity Vulnerabilities Patched in Tenable Nessus Agent

Posted on June 16, 2025June 16, 2025 By CWS

Tenable has launched patches for 3 high-severity vulnerabilities in Nessus Agent for Home windows that may very well be exploited to carry out file operations and execute code with elevated privileges.

Tracked as CVE-2025-36631 (CVSS rating of 8.4), the primary bug might permit customers logged in to non-administrative accounts to overwrite arbitrary native system recordsdata with log content material, with System privileges.

The second flaw, CVE-2025-36632 (CVSS rating of seven.8), permits non-administrative customers to execute arbitrary code with System privileges.

Lastly, CVE-2025-36633 (CVSS rating of 8.8) permits customers in a non-administrative place to arbitrarily delete native system recordsdata, additionally with System privileges.

Profitable exploitation of the difficulty might permit customers to escalate their privileges on the affected machine, Tenable says.

The three vulnerabilities affect Nessus Agent variations 10.8.4 and earlier and have been resolved with the discharge of model 10.8.5, which is obtainable from Tenable’s obtain portal.

The corporate makes no point out of any of those vulnerabilities being exploited within the wild, however customers are suggested to replace their deployments as quickly as doable.

Tenable Nessus brokers are light-weight packages put in regionally to gather info from belongings. They can be utilized to scan for safety defects, compliance points, and different sorts of info.Commercial. Scroll to proceed studying.

In early January, Tenable disabled agent variations 10.8.0 and 10.8.1, after discovering that they have been going offline following a differential plugin replace. The corporate instructed SecurityWeek on the time that it was not a safety incident and that no buyer was adversely impacted.

Associated: Essential Vulnerabilities Patched in Pattern Micro Apex Central, Endpoint Encryption

Associated: Palo Alto Networks Patches Privilege Escalation Vulnerabilities

Associated: Fortinet, Ivanti Patch Excessive-Severity Vulnerabilities

Associated: Cisco Patches Essential ISE Vulnerability With Public PoC

Security Week News Tags:Agent, HighSeverity, Nessus, Patched, Tenable, Vulnerabilities

Post navigation

Previous Post: Canadian Airline WestJet Hit by Cyberattack
Next Post: North Korean APT Hackers Attacking Ukrainian Government Agencies to Steal Login Credentials

Related Posts

Suspected DoppelPaymer Ransomware Group Member Arrested Security Week News
Paragon ‘Graphite’ Spyware Linked to Zero-Click Hacks on Newest iPhones Security Week News
Alleged Conti, TrickBot Gang Leader Unmasked Security Week News
Swimlane Raises $45 Million for Security Automation Platform Security Week News
With Retail Cyberattacks on the Rise, Customers Find Orders Blocked and Shelves Empty Security Week News
Webinar Today: Redefining Vulnerability Management With Exposure Validation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Washington Post Journalists’ Microsoft Accounts Hacked in Targetetd Cyberattack
  • Google’s $32 Billion Wiz Deal Draws DOJ Antitrust Scrutiny: Report
  • Former GCHQ Intern Jailed for Seven Years After Copying Top Secret Files to Mobile Phone
  • Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment
  • Darknet Market Archetyp Dismantled by Authorities in Joint Action ‘Operation Deep Sentinel’

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2025
  • May 2025

Recent Posts

  • Washington Post Journalists’ Microsoft Accounts Hacked in Targetetd Cyberattack
  • Google’s $32 Billion Wiz Deal Draws DOJ Antitrust Scrutiny: Report
  • Former GCHQ Intern Jailed for Seven Years After Copying Top Secret Files to Mobile Phone
  • Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment
  • Darknet Market Archetyp Dismantled by Authorities in Joint Action ‘Operation Deep Sentinel’

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News