Description
When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Tenable has released Nessus Agent 10.6.4 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus-agents ).
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31881 | When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2024-09 |
|
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-01T20:05:08.354Z
Reserved: 2024-04-03T21:19:32.010Z
Link: CVE-2024-3291
Updated: 2024-08-01T20:05:08.354Z
Status : Deferred
Published: 2024-05-17T17:15:07.740
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-3291
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD