Tenable Nessus Security Updates 22 January 2023

Tenable Nessus has released updated versions (Nessus 10.4.2, 8.15.8) to fix a privilege escalation vulnerability.

The mentioned vulnerability could allow the authenticated attacker to execute a specially crafted file to obtain root or NT AUTHORITY/SYSTEM privileges on the affected Nessus host.

Tenable Nessus Privilege Escalation Vulnerability (CVE-2023-0101):

• CVSS: 9.1

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: High

• User Interaction: None

• Consequences: Gain Privilege

Affected Products:

• Nessus 10.4.1 and earlier.

• Nessus 8.15.7 and earlier.

Vulnerabilities
  • CVE-2023-0101
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Tenable Nessus Downloads

References