When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
2025-05-23T16:15:24.997
2025-10-23T14:35:21.220
Analyzed
CVSSv3.1: 7.0 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | tenable | nessus_network_monitor | < 6.5.1 | Yes |
| Operating System | microsoft | windows | - | No |