CVE-2025-36630: Local Privilege Escalation
Published Jul 1, 2025
·Updated
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
Affected Software
3 affected components
Tenable Nessus<10.8.5
All of the following
Tenable Nessus<10.8.5
Microsoft Windows
Remediation
Information
Tenable has released Nessus 10.8.5 and Nessus 10.9.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/nessus
Event History
Jul 1, 2025
CVE Published
via MITRE·11:11 PM
Data Sourced
via MITRE·11:11 PM
RemedyDescriptionSeverityWeakness
Jul 2, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-36630?
CVE-2025-36630 is rated as a high severity vulnerability due to its potential for allowing unauthorized file overwriting at SYSTEM privilege.
2
How do I fix CVE-2025-36630?
To fix CVE-2025-36630, update Tenable Nessus to version 10.8.5 or later.
3
Who is affected by CVE-2025-36630?
CVE-2025-36630 affects Tenable Nessus versions prior to 10.8.5 on Windows hosts.
4
What is the impact of CVE-2025-36630?
The impact of CVE-2025-36630 allows non-administrative users to overwrite arbitrary local system files, compromising system integrity.
5
Is CVE-2025-36630 present in all Tenable Nessus versions?
No, CVE-2025-36630 is only present in Tenable Nessus versions prior to 10.8.5.