CVE-2025-36631: Local Privilege Escalation
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36631?
CVE-2025-36631 has been assigned a high severity rating due to its potential for leading to arbitrary file overwrites with SYSTEM privileges.
How do I fix CVE-2025-36631?
To mitigate CVE-2025-36631, update the Tenable Agent to version 10.8.5 or later.
Who is affected by CVE-2025-36631?
CVE-2025-36631 affects users of Tenable Agent versions prior to 10.8.5 running on Windows hosts.
What is the impact of CVE-2025-36631?
The impact of CVE-2025-36631 allows non-administrative users to overwrite system files, potentially compromising system integrity and security.
Is there a workaround for CVE-2025-36631?
While updating is the recommended solution, restricting non-administrative users’ access may serve as a temporary workaround for CVE-2025-36631.