CVE-2024-3290: Race Condition
Published May 17, 2024
·Updated
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host
Affected Software
1 affected component
Tenable Nessus
Remediation
Information
Tenable has released Nessus 10.7.3 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus ).
Event History
May 17, 2024
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3290?
CVE-2024-3290 is classified as a high-severity vulnerability.
2
How do I fix CVE-2024-3290?
To fix CVE-2024-3290, ensure that you are running the latest version of Tenable Nessus that includes security patches addressing this vulnerability.
3
Who is affected by CVE-2024-3290?
CVE-2024-3290 affects authenticated, local users on Windows systems running Tenable Nessus.
4
What kind of attack can be executed due to CVE-2024-3290?
CVE-2024-3290 could allow an attacker to execute arbitrary code on the Nessus host during installation.
5
Is authentication required to exploit CVE-2024-3290?
Yes, exploitation of CVE-2024-3290 requires the attacker to be authenticated on the Windows Nessus host.