First published: Wed Nov 01 2023(Updated: )
Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Linux hosts.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Tenable Nessus | <10.6.2 | |
Tenable Nessus Agent | <10.4.3 | |
Any of | ||
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5847 is a vulnerability that allows an attacker to escalate privileges on Windows and Linux hosts during installation or upgrade.
CVE-2023-5847 has a severity score of 7.3, which is classified as high.
The vulnerability affects Tenable Nessus versions up to 10.6.2 and Tenable Nessus Agent versions up to 10.4.3.
An attacker can exploit CVE-2023-5847 by loading a specially crafted file during the installation or upgrade process.
Windows and Linux hosts are vulnerable to CVE-2023-5847, but the Linux kernel and Microsoft Windows themselves are not vulnerable.