[R1] Nessus Agent 8.2.5 Fixes Multiple Vulnerabilities

Related Vulnerabilities: CVE-2021-20099   CVE-2021-20100  

Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus Agent host.

Synopsis

Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus Agent host.

Solution

Tenable has released Nessus Agent 8.2.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus-agents).