[R2] Nessus 7.0.3 Fixes One Vulnerability

Related Vulnerabilities: CVE-2018-1141  

When installing Nessus to a directory outside of the default location, Nessus did not enforce secure permissions for sub-directories on Windows operating systems. This could allow for local privilege escalation if users had not secured the directories in the installation location.

Synopsis

When installing Nessus to a directory outside of the default location, Nessus did not enforce secure permissions for sub-directories on Windows operating systems. This could allow for local privilege escalation if users had not secured the directories in the installation location.

Solution

Tenable has released Nessus version 7.0.3 address this issue. To update your Nessus installation, follow these steps:
• Download the appropriate installation file to the system hosting Nessus Professional or Nessus Manager, available at the Tenable Support Portal (https://support.tenable.com/support-center/index.php?x=&mod_id=200)
• Stop the Nessus service.
• Install according to your operating system procedures.
• Restart the Nessus service.