QID 375654
QID 375654: Tenable Nessus Multiple Vulnerabilities (TNS-2021-11)
Nessus is a proprietary vulnerability scanner.
Nessus versions 8.14.0 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host.
Additionally, two third-party components (expat, sqlite) were found to contain vulnerabilities, and updated versions have been made available by the providers.
Affected Versions:
Nessus versions prior to 8.15.0
QID Detection Logic (Authenticated):
This QID checks for the existence of vulnerable versions of nessus in registry.
Successful exploitation of these vulnerabilities affects the confidentiality, Integrity and Availability.
Solution
The vendor has issued a fix in Nessus version 8.15.0. Refer to Nessus advisory TNS-2021-11 to address this issue and obtain more information.
Vendor References
- tns-2021-11 -
www.tenable.com/security/tns-2021-11
CVEs related to QID 375654
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TNS-2021-11 |
|