CVE-2024-3289

When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
Configurations

No configuration.

History

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://www.tenable.com/security/tns-2024-08 - () https://www.tenable.com/security/tns-2024-08 -
Summary
  • (es) Al instalar Nessus en un directorio fuera de la ubicación predeterminada en un host de Windows, las versiones de Nessus anteriores a la 10.7.3 no aplicaban permisos seguros para los subdirectorios. Esto podría permitir una escalada de privilegios locales si los usuarios no hubieran protegido los directorios en la ubicación de instalación no predeterminada.

17 May 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 17:15

Updated : 2024-11-21 09:29


NVD link : CVE-2024-3289

Mitre link : CVE-2024-3289

CVE.ORG link : CVE-2024-3289


JSON object : View

Products Affected

No product.

CWE
CWE-281

Improper Preservation of Permissions