CVE-2025-36633: Local Privilege Escalation
Published Jun 13, 2025
·Updated
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.
Affected Software
3 affected components
Tenable Tenable Agent<10.8.5
All of the following
Tenable Nessus Agent<10.8.5
Microsoft Windows
Remediation
Information
Tenable has released Agent 10.8.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/nessus-agents
Event History
Jun 13, 2025
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What are the implications of CVE-2025-36633?
CVE-2025-36633 allows non-administrative users to delete local system files with SYSTEM privileges, potentially leading to local privilege escalation.
2
How can I mitigate the risks associated with CVE-2025-36633?
To mitigate risks from CVE-2025-36633, upgrade to Tenable Agent version 10.8.5 or later.
3
Who is affected by CVE-2025-36633?
CVE-2025-36633 affects all users of Tenable Agent versions prior to 10.8.5 on Windows hosts.
4
What specific versions are impacted by CVE-2025-36633?
Versions of Tenable Agent prior to 10.8.5 are impacted by CVE-2025-36633.
5
Is there a patch available for CVE-2025-36633?
Yes, a patch is available in version 10.8.5 of Tenable Agent which fixes CVE-2025-36633.