CVE-2025-24917: Improper Access Control leads to Local Privilege Escalation
Published May 23, 2025
·Updated
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.
Affected Software
3 affected components
Tenable Network Monitor<6.5.1
All of the following
Tenable Nessus Network Monitor<6.5.1
Microsoft Windows
Remediation
Information
Tenable has released Tenable Network Monitor 6.5.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus-network-monitor https://www.tenable.com/downloads/nessus-network-monitor ).
Event History
May 23, 2025
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24917?
CVE-2025-24917 has been rated as a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2025-24917?
To fix CVE-2025-24917, upgrade Tenable Network Monitor to version 6.5.1 or later.
3
What versions of Tenable Network Monitor are affected by CVE-2025-24917?
CVE-2025-24917 affects Tenable Network Monitor versions prior to 6.5.1.
4
Can a non-administrative user exploit CVE-2025-24917?
Yes, a non-administrative user can exploit CVE-2025-24917 to run arbitrary code with SYSTEM privileges.
5
What could happen if CVE-2025-24917 is successfully exploited?
If exploited, CVE-2025-24917 could lead to unauthorized access and control over the system by allowing local privilege escalation.