First published: Fri Jan 20 2023(Updated: )
A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker could potentially execute a specially crafted file to obtain root or NT AUTHORITY / SYSTEM privileges on the Nessus host.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Nessus | >=8.10.1<8.15.8 | |
Tenable Nessus | >=10.0.0<10.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this privilege escalation vulnerability in Nessus is CVE-2023-0101.
The severity of CVE-2023-0101 is high with a CVSS score of 8.8.
Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1 are affected by CVE-2023-0101.
An authenticated attacker could potentially execute a specially crafted file to obtain root or NT AUTHORITY / SYSTEM privileges on the Nessus host.
You can find more information about CVE-2023-0101 at the following references: [Tenable Security Advisory TNS-2023-01](https://www.tenable.com/security/tns-2023-01) and [Tenable Security Advisory TNS-2023-02](https://www.tenable.com/security/tns-2023-02).