Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITYSYSTEM on Windows hosts by replacing a specially crafted file.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nessus_network_monitor | Tenable | * | 6.3.0 (excluding) |