Vulnerability Description
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Nessus Network Monitor | < 6.5.1 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/tns-2025-10Vendor Advisory
FAQ
What is CVE-2025-24916?
CVE-2025-24916 is a vulnerability with a CVSS score of 7.0 (HIGH). When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could ...
How severe is CVE-2025-24916?
CVE-2025-24916 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24916?
Check the references section above for vendor advisories and patch information. Affected products include: Tenable Nessus Network Monitor, Microsoft Windows.