logo

Nessus Agent Vulnerability on Windows Allows Arbitrary Code Execution as SYSTEM

ID: 5de9201c-8580-5feb-b24a-5ebfc2e5704f

STIX ID: report--5de9201c-8580-5feb-b24a-5ebfc2e5704f

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: AnuPriya

...
...

High-severity Windows vulnerability (CVE-2026-33694) was disclosed in Tenable Nessus Agent allowing local attackers to abuse filesystem junctions to induce arbitrary file deletions by the agent running as SYSTEM, which can be escalated to arbitrary code execution; Tenable fixed the issue in Nessus Agent 11.1.3 (released 2026-04-23), and administrators are urged to patch and monitor for malicious junction creation and filesystem permission anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.