- Description
- A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.
- Source
- vulnreport@tenable.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7779DB7-0EDD-46C6-B140-B6C9B7DC4DD6",
"versionEndIncluding": "8.12.0",
"versionStartIncluding": "8.9.0"
},
{
"criteria": "cpe:2.3:a:tenable:nessus_agent:8.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E9B50E8-711C-4812-9D54-D3CC81294F75"
},
{
"criteria": "cpe:2.3:a:tenable:nessus_agent:8.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E316EC25-E5EA-4EFA-9D01-E0617D565FD2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]