CVE-2025-24916: Improper Access Control leads to Local Priviledge Escalation
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24916?
CVE-2025-24916 has been classified as a local privilege escalation vulnerability.
How do I fix CVE-2025-24916?
To fix CVE-2025-24916, upgrade to Tenable Network Monitor version 6.5.1 or later.
Who is affected by CVE-2025-24916?
CVE-2025-24916 affects users of Tenable Network Monitor versions prior to 6.5.1 installed in non-default locations on Windows.
What allows the exploitation of CVE-2025-24916?
The vulnerability is due to the lack of enforced secure permissions for sub-directories during installation.
What are the risks associated with CVE-2025-24916?
The risks include potential local privilege escalation that could compromise system security.