CVE-2025-36632: Local Privilege Escalation
Published Jun 16, 2025
·Updated
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.
Affected Software
3 affected components
Tenable Tenable Agent<10.8.5
All of the following
Tenable Nessus Agent<10.8.5
Microsoft Windows
Remediation
Information
Tenable has released Agent 10.8.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/nessus-agents
Event History
Jun 16, 2025
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-36632?
CVE-2025-36632 is considered to have a high severity level due to the potential for code execution with SYSTEM privileges by non-administrative users.
2
How do I fix CVE-2025-36632?
To mitigate CVE-2025-36632, upgrade Tenable Agent to version 10.8.5 or later.
3
What versions are affected by CVE-2025-36632?
CVE-2025-36632 affects Tenable Agent versions prior to 10.8.5.
4
Who is affected by CVE-2025-36632?
Users running affected versions of Tenable Agent on Windows hosts are at risk from CVE-2025-36632.
5
What type of vulnerability is CVE-2025-36632?
CVE-2025-36632 is a code execution vulnerability that allows non-administrative users to execute code with elevated SYSTEM privileges.