[R1] Nessus 8.15.0 Fixes Multiple Vulnerabilities

Related Vulnerabilities: CVE-2018-20843   CVE-2019-15903   CVE-2019-16168   CVE-2021-20099   CVE-2021-20100  

Nessus versions 8.14.0 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. Additionally, two third-party components (expat, sqlite) were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution, and in line with best practice, Tenable has implemented fixes for the privilege escalation vulnerabilities, as well as upgraded the bundled third-party components to address the potential impact of these issues. Nessus 8.15.0 addresses the privilege escalation issues, updates expat to version 2.2.10 and sqlite to version 3.34.1.

Synopsis

Nessus versions 8.14.0 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host.

Additionally, two third-party components (expat, sqlite) were found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution, and in line with best practice, Tenable has implemented fixes for the privilege escalation vulnerabilities, as well as upgraded the bundled third-party components to address the potential impact of these issues. Nessus 8.15.0 addresses the privilege escalation issues, updates expat to version 2.2.10 and sqlite to version 3.34.1.

Solution

Tenable has released Nessus 8.15.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus).