CVE-2025-36640
Tenable Nessus vulnerability analysis and mitigation

Overview

CVE-2025-36640 is a local privilege escalation vulnerability in the Nessus Agent Tray App on Windows hosts, classified as Improper Privilege Management (CWE-269). The flaw is triggered during the installation or uninstallation process of the Tray App component. Affected versions include Nessus Agent prior to 10.9.3 and Nessus Agent 11.0.0 through 11.0.2. The vulnerability was reported to Tenable on 2025-11-03, confirmed on 2025-12-09, and patched on 2026-01-07, with the CVE published on 2026-01-13. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.3 (High) (Tenable Advisory).

Technical details

The root cause is improper privilege management (CWE-269) during the install/uninstall lifecycle of the Nessus Agent Tray App on Windows. A low-privileged local user can exploit conditions present during the installation or uninstallation process to escalate their privileges, potentially gaining elevated system access. The CVSS v4.0 vector indicates attack requirements are present (AT:P), meaning specific preconditions — such as timing the exploit to coincide with the install/uninstall operation — must be met. The vulnerability was discovered and reported by the Lockheed Martin Red Team, and proof-of-concept exploit maturity is noted in the CVSS v4.0 scoring (Tenable Advisory).

Impact

Successful exploitation allows a low-privileged local attacker to escalate privileges on the affected Windows host, with high impact to confidentiality, integrity, and availability. The CVSS v3.1 scope is marked as "Changed," indicating the vulnerability can affect resources beyond the vulnerable component itself. This could enable an attacker to gain SYSTEM-level access, facilitating credential theft, persistence, lateral movement within the network, or full host compromise (Tenable Advisory).

Exploitability

The CVSS v4.0 exploit maturity is rated as Proof-of-Concept (E:P), indicating that PoC exploit code or techniques are publicly known. Exploitation requires local access with low privileges and the presence of specific conditions (install/uninstall activity). The EPSS score is approximately 0.012% (0.000120), suggesting low but non-zero probability of exploitation in the wild. No evidence of active in-the-wild exploitation or CISA KEV catalog listing has been identified at this time (Tenable Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify Windows hosts running Nessus Agent versions prior to 10.9.3 or between 11.0.0 and 11.0.2 with the Tray App component installed.
  2. Gain local access: Obtain a low-privileged user account on the target Windows system (e.g., via phishing, credential reuse, or other initial access techniques).
  3. Monitor or trigger install/uninstall: Wait for or trigger an installation or uninstallation event of the Nessus Agent Tray App, which introduces the exploitable privilege management flaw.
  4. Exploit privilege escalation: During the install/uninstall process, leverage the improper privilege management condition (e.g., insecure file/directory permissions, DLL hijacking, or unquoted service path) to execute attacker-controlled code in a higher-privileged context.
  5. Achieve elevated access: Obtain SYSTEM or administrator-level privileges on the host, enabling full control of the system (Tenable Advisory).

Indicators of compromise

  • Logs: Windows Event Logs showing unexpected privilege escalation events (Event ID 4672, 4673) coinciding with Nessus Agent installation or uninstallation activity; unusual process creation events (Event ID 4688) spawned during Nessus Agent Tray App install/uninstall.
  • File System: Unexpected files or DLLs placed in Nessus Agent installation directories (e.g., C:\Program Files\Tenable\Nessus Agent\) by non-administrative users; modified or replaced binaries in the Tray App installation path.
  • Process: Unusual child processes spawned by the Nessus Agent installer or Tray App process running with elevated privileges; processes running as SYSTEM that were initiated by a low-privileged user account.
  • Registry: Unexpected modifications to registry keys associated with Nessus Agent services or startup entries during or after installation/uninstallation events.

Mitigation and workarounds

Tenable has released patched versions Nessus Agent 11.0.3 and Nessus Agent 10.9.3 to address this vulnerability. Users running Nessus Agent prior to 10.9.3 or versions 11.0.0 through 11.0.2 should upgrade immediately using the Tenable Downloads Portal. No specific configuration-based workaround is documented; upgrading to a fixed version is the recommended and primary remediation action (Tenable Advisory).

Community reactions

The vulnerability was credited to the Lockheed Martin Red Team, indicating it was discovered through professional red team engagement. Coverage appeared on The Hacker Wire and was noted on Mastodon security channels shortly after disclosure. The Egyptian Financial Sector CIRT also published a Tenable security update notice referencing this advisory. Community reaction has been moderate, consistent with a local privilege escalation in a security tool affecting Windows environments (Tenable Advisory).

Additional resources


SourceThis report was generated using AI

Related Tenable Nessus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36640HIGH7.3
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesJan 13, 2026
CVE-2025-36630HIGH7.1
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesJul 02, 2025
CVE-2025-36625MEDIUM4.3
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesApr 18, 2025
CVE-2026-57587LOW2.9
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesJun 25, 2026
CVE-2026-57588LOW1.8
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesJun 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management