CVE-2014-2848: Tenable Nessus

Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.

A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.

Affected products

  • Tenable Nessus: version 5.2.1 only
  • Tenable Plugin-Set: up to and including 201402092115

Published 2014-04-11. Last modified 2026-06-17.