QID 375654

QID 375654: Tenable Nessus Multiple Vulnerabilities (TNS-2021-11)

Nessus is a proprietary vulnerability scanner.

Nessus versions 8.14.0 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host.
Additionally, two third-party components (expat, sqlite) were found to contain vulnerabilities, and updated versions have been made available by the providers.

Affected Versions:
Nessus versions prior to 8.15.0

QID Detection Logic (Authenticated):
This QID checks for the existence of vulnerable versions of nessus in registry.

Successful exploitation of these vulnerabilities affects the confidentiality, Integrity and Availability.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    The vendor has issued a fix in Nessus version 8.15.0. Refer to Nessus advisory TNS-2021-11 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    TNS-2021-11 URL Logo www.tenable.com/security/tns-2021-11