Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9wpx-f5qr-7rcr

Опубликовано: 23 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.

When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.

EPSS

Процентиль: 1%
0.00011
Низкий

7 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7
nvd
9 месяцев назад

When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.

EPSS

Процентиль: 1%
0.00011
Низкий

7 High

CVSS3

Дефекты

CWE-284