[R1] Nessus 8.12.1 Fixes One Vulnerability

Related Vulnerabilities: CVE-2020-5793  

A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.

Synopsis

A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.

Solution

Tenable has included a fix in Nessus 8.12.1 to address this issue. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus).