CVE-2018-1141: Tenable Nessus
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the installation location.
Affected products
- Tenable Nessus: before 7.0.3 (fixed in 7.0.3)
Published 2018-03-20. Last modified 2026-06-17.