Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Tenable has released Nessus Agent 10.8.3 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus-agents ).
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7246 | When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. |
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2025-02 |
|
Fri, 21 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Mar 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-02-26T19:09:18.159Z
Reserved: 2025-01-28T20:09:40.193Z
Link: CVE-2025-24915
Updated: 2025-03-21T15:22:09.368Z
Status : Deferred
Published: 2025-03-21T15:15:42.020
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-24915
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:13Z
EUVD