CVE-2025-36632
Tenable Nessus Agent vulnerability analysis and mitigation

Overview

CVE-2025-36632 is a local privilege escalation vulnerability in Tenable Agent (Nessus Agent) for Windows that allows a non-administrative user to execute arbitrary code with SYSTEM privileges. It affects all Tenable Agent versions prior to 10.8.5 on Windows hosts. The vulnerability was reported to Tenable and patched on June 12, 2025, with the advisory published on June 16, 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Tenable Advisory).

Technical details

The root cause is classified as CWE-276 (Incorrect Default Permissions), meaning the Tenable Agent installation on Windows sets overly permissive access controls on files or directories used by the agent service, which runs as SYSTEM (Tenable Advisory). A low-privileged local user can exploit these misconfigured permissions to place or manipulate content that is subsequently executed by the SYSTEM-level service process. This is consistent with MITRE ATT&CK technique T1574.010 (Services File Permissions Weakness), where an attacker abuses weak service-related file permissions to achieve privilege escalation (Feedly). No authentication beyond a standard local user account is required, and no user interaction is needed. CVE-2025-36632 is one of three related vulnerabilities (alongside CVE-2025-36631 and CVE-2025-36633) addressed in the same advisory, all sharing the same root cause in the Tenable Agent Windows installation.

Impact

Successful exploitation allows a non-administrative local user to escalate privileges to SYSTEM level on the affected Windows host, granting complete control over the operating system. This results in high confidentiality, integrity, and availability impact — an attacker can read sensitive data, modify or delete system files, install malware, create backdoor accounts, and potentially use the compromised host as a pivot point for lateral movement within the network (Tenable Advisory, SecurityWeek).

Exploitability

No public proof-of-concept exploit code has been identified for CVE-2025-36632 at this time, and there is no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.011% (0.000110), indicating a currently low probability of exploitation in the near term. Exploitation requires local access to the target Windows system with at least a standard (non-administrative) user account, which limits the attack surface compared to remotely exploitable vulnerabilities (Tenable Advisory).

Exploitation steps

  1. Reconnaissance: Identify Windows hosts running Tenable Agent (Nessus Agent) versions prior to 10.8.5. This can be done by checking installed software via wmic product get name,version or reviewing the Tenable Agent installation directory (typically C:\Program Files\Tenable\Nessus Agent\).
  2. Identify misconfigured permissions: Use tools such as icacls, accesschk.exe (Sysinternals), or PowerShell Get-Acl to enumerate file and directory permissions within the Tenable Agent installation path, looking for directories or files writable by non-administrative users that are used by the SYSTEM-level agent service.
  3. Craft malicious payload: Prepare a malicious executable or DLL designed to perform the desired action (e.g., add a new administrative user, establish a reverse shell, or install a backdoor).
  4. Place payload: Write or replace the identified writable file/directory with the malicious payload, exploiting the incorrect default permissions (CWE-276).
  5. Trigger execution: Wait for or trigger the Tenable Agent service to load or execute the manipulated file. Since the service runs as SYSTEM, the payload executes with SYSTEM privileges, completing the privilege escalation (Tenable Advisory).

Indicators of compromise

  • File System: Unexpected or recently modified files within the Tenable Agent installation directory (e.g., C:\Program Files\Tenable\Nessus Agent\); presence of unknown executables or DLLs in agent subdirectories; file timestamps inconsistent with the agent installation date.
  • Process: Unusual child processes spawned by the Tenable Agent service process (e.g., cmd.exe, powershell.exe, net.exe) with SYSTEM privileges; unexpected processes running as SYSTEM that are not part of normal agent operation.
  • Logs: Windows Security Event Log entries showing privilege use (Event ID 4672) or new account creation (Event ID 4720) associated with the Tenable Agent service account; Windows System Event Log entries for unexpected service restarts or failures.
  • Network: Outbound connections from the Tenable Agent host to unknown external IP addresses or C2 infrastructure, particularly from processes running as SYSTEM.

Mitigation and workarounds

Tenable has released Nessus Agent version 10.8.5 (released June 12, 2025) to address CVE-2025-36632 along with two related vulnerabilities (CVE-2025-36631 and CVE-2025-36633). Organizations should upgrade all Windows-based Tenable Agent deployments to version 10.8.5 or later immediately via the Tenable Downloads Portal. As interim measures, restrict local user access to Windows hosts running Tenable Agent, apply the principle of least privilege, and audit file system permissions on the agent installation directory. Tenable's updated release notes include additional mitigation information (Tenable Advisory).

Community reactions

SecurityWeek covered the vulnerability as part of a broader report on high-severity flaws patched in Tenable Nessus Agent, noting the privilege escalation risk on Windows hosts (SecurityWeek). The Hacker News included the vulnerability in its weekly security recap (The Hacker News). Security community members on Mastodon (infosec.exchange) flagged the advisory shortly after publication. Cyware's daily threat intelligence briefing for June 16, 2025 also highlighted the issue. Overall community sentiment reflects moderate concern given the SYSTEM-level privilege escalation potential, though the local-only attack vector limits the urgency compared to remotely exploitable flaws.

Additional resources


SourceThis report was generated using AI

Related Tenable Nessus Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-3292HIGH8.2
  • Tenable Nessus Agent logoTenable Nessus Agent
  • cpe:2.3:a:tenable:nessus_agent
NoYesMay 17, 2024
CVE-2025-36632HIGH7.8
  • Tenable Nessus Agent logoTenable Nessus Agent
  • cpe:2.3:a:tenable:nessus_agent
NoYesJun 16, 2025
CVE-2025-36633HIGH7.8
  • Tenable Nessus Agent logoTenable Nessus Agent
  • cpe:2.3:a:tenable:nessus_agent
NoYesJun 13, 2025
CVE-2025-36631HIGH7.8
  • Tenable Nessus Agent logoTenable Nessus Agent
  • cpe:2.3:a:tenable:nessus_agent
NoYesJun 13, 2025
CVE-2026-2026MEDIUM5.4
  • Tenable Nessus Agent logoTenable Nessus Agent
  • cpe:2.3:a:tenable:nessus_agent
NoYesFeb 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management