CVE-2020-5793: High severity Tenable Nessus vulnerability
A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5793?
CVE-2020-5793 is a vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows that could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory.
How can an attacker exploit CVE-2020-5793?
An attacker could exploit CVE-2020-5793 by copying user-supplied files to a specially constructed path in a specifically named user directory.
What is the severity of CVE-2020-5793?
The severity of CVE-2020-5793 is high with a severity score of 7.8.
Which versions of Nessus and Nessus Agent are affected by CVE-2020-5793?
Nessus versions 8.9.0 through 8.12.0 for Windows and Nessus Agent 8.0.0 and 8.1.0 for Windows are affected by CVE-2020-5793.
How can I fix CVE-2020-5793?
To fix CVE-2020-5793, it is recommended to update to a version of Nessus or Nessus Agent that is not affected by the vulnerability.