Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Tenable has released Nessus 10.8.4 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/nessus https://www.tenable.com/downloads/nessus
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11906 | When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. - CVE-2025-24914 |
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2025-05 |
|
Fri, 18 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Apr 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. - CVE-2025-24914 | |
| Title | Local Priviledge Escalation | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-02-26T18:28:09.421Z
Reserved: 2025-01-28T20:09:40.192Z
Link: CVE-2025-24914
Updated: 2025-04-18T18:32:48.280Z
Status : Deferred
Published: 2025-04-18T19:15:45.510
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-24914
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:14Z
EUVD