CVE-2025-36633 HIGH

CVE-2025-36633: Local Privilege Escalation

Vendor Tenable
Product Agent
Weakness CWE-269
Published June 13, 2025
Last update February 26, 2026

CVSS base score

8.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.

Key dates

02Disclosure timeline

June 13, 2025 CVE published
February 26, 2026 Record updated