CVE-2025-24914

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 276

Summary

CVE-2025-24914 is a vulnerability affecting Nessus, a vulnerability scanning tool, on Windows hosts. Prior to version 10.8.4, Nessus installed in non-default locations did not properly enforce secure permissions for sub-directories. This oversight could potentially enable local privilege escalation if users failed to secure these directories themselves. Unauthorized users with access to the non-default installation location could exploit this vulnerability to gain elevated privileges, posing a significant risk to system security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share