[R3] Nessus 6.10.4 Fixes One Vulnerability

Related Vulnerabilities: CVE-2017-7199  

Nessus was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode. This may allow an attacker to gain administrative privileges on the system hosting a Nessus agent. This is tracked internally as NES-6023.

Synopsis

Nessus was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode. This may allow an attacker to gain administrative privileges on the system hosting a Nessus agent. This is tracked internally as NES-6023.

Solution

Tenable has released Nessus version 6.10.4 that corresponds to the supported operating systems and architectures. To update your Nessus installation, follow these steps:

Note that only agents are impacted by this vulnerability, not scanners. If Nessus Manager is updated then auto updates will be deployed to the agents as well. If the agent is on Tenable.io then all of the agents will receive the updates.