
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36632 is a local privilege escalation vulnerability in Tenable Agent (Nessus Agent) for Windows that allows a non-administrative user to execute arbitrary code with SYSTEM privileges. It affects all Tenable Agent versions prior to 10.8.5 on Windows hosts. The vulnerability was reported to Tenable and patched on June 12, 2025, with the advisory published on June 16, 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Tenable Advisory).
The root cause is classified as CWE-276 (Incorrect Default Permissions), meaning the Tenable Agent installation on Windows sets overly permissive access controls on files or directories used by the agent service, which runs as SYSTEM (Tenable Advisory). A low-privileged local user can exploit these misconfigured permissions to place or manipulate content that is subsequently executed by the SYSTEM-level service process. This is consistent with MITRE ATT&CK technique T1574.010 (Services File Permissions Weakness), where an attacker abuses weak service-related file permissions to achieve privilege escalation (Feedly). No authentication beyond a standard local user account is required, and no user interaction is needed. CVE-2025-36632 is one of three related vulnerabilities (alongside CVE-2025-36631 and CVE-2025-36633) addressed in the same advisory, all sharing the same root cause in the Tenable Agent Windows installation.
Successful exploitation allows a non-administrative local user to escalate privileges to SYSTEM level on the affected Windows host, granting complete control over the operating system. This results in high confidentiality, integrity, and availability impact — an attacker can read sensitive data, modify or delete system files, install malware, create backdoor accounts, and potentially use the compromised host as a pivot point for lateral movement within the network (Tenable Advisory, SecurityWeek).
No public proof-of-concept exploit code has been identified for CVE-2025-36632 at this time, and there is no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.011% (0.000110), indicating a currently low probability of exploitation in the near term. Exploitation requires local access to the target Windows system with at least a standard (non-administrative) user account, which limits the attack surface compared to remotely exploitable vulnerabilities (Tenable Advisory).
wmic product get name,version or reviewing the Tenable Agent installation directory (typically C:\Program Files\Tenable\Nessus Agent\).icacls, accesschk.exe (Sysinternals), or PowerShell Get-Acl to enumerate file and directory permissions within the Tenable Agent installation path, looking for directories or files writable by non-administrative users that are used by the SYSTEM-level agent service.C:\Program Files\Tenable\Nessus Agent\); presence of unknown executables or DLLs in agent subdirectories; file timestamps inconsistent with the agent installation date.cmd.exe, powershell.exe, net.exe) with SYSTEM privileges; unexpected processes running as SYSTEM that are not part of normal agent operation.Tenable has released Nessus Agent version 10.8.5 (released June 12, 2025) to address CVE-2025-36632 along with two related vulnerabilities (CVE-2025-36631 and CVE-2025-36633). Organizations should upgrade all Windows-based Tenable Agent deployments to version 10.8.5 or later immediately via the Tenable Downloads Portal. As interim measures, restrict local user access to Windows hosts running Tenable Agent, apply the principle of least privilege, and audit file system permissions on the agent installation directory. Tenable's updated release notes include additional mitigation information (Tenable Advisory).
SecurityWeek covered the vulnerability as part of a broader report on high-severity flaws patched in Tenable Nessus Agent, noting the privilege escalation risk on Windows hosts (SecurityWeek). The Hacker News included the vulnerability in its weekly security recap (The Hacker News). Security community members on Mastodon (infosec.exchange) flagged the advisory shortly after publication. Cyware's daily threat intelligence briefing for June 16, 2025 also highlighted the issue. Overall community sentiment reflects moderate concern given the SYSTEM-level privilege escalation potential, though the local-only attack vector limits the urgency compared to remotely exploitable flaws.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."