B
今週中
Tenableは、Windows版Nessus Agentの「Nessus Agent Tray App」における権限昇格の脆弱性(CVE-2025-36640…
📌 一言でいうと
Tenableは、Windows版Nessus Agentの「Nessus Agent Tray App」における権限昇格の脆弱性(CVE-2025-36640)を修正しました。この脆弱性は、コンポーネントのインストールまたはアンインストール時に悪用される可能性があり、攻撃者に高い権限を与えるリスクがあります。影響を受けるバージョンは、Windows版の10.9.3未満および11.0.0から11.0.2までです。
🔍該当判定
- 脆弱性診断ツール「Nessus Agent」をWindows端末にインストールして利用している
- Nessus Agentのバージョンが 10.9.3 未満である
- Nessus Agentのバージョンが 11.0.0 から 11.0.2 の間である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーのセキュリティアドバイザリに従い、Nessus Agentを最新バージョンにアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Tenable Nessus Agent CVE-2025-36640 対応について
お疲れさまです。Nessus Agentの脆弱性に関する情報共有です。
■ 概要
Windows版Nessus Agentの「Nessus Agent Tray App」において、権限昇格が可能な脆弱性(CVE-2025-36640)が報告されました。インストール/アンインストール処理の不備を悪用し、特権昇格が行われる可能性があります。
■ 影響範囲
- Nessus Agent (Windows版) バージョン 10.9.3 未満
- Nessus Agent (Windows版) バージョン 11.0.0 ~ 11.0.2
■ 対応手順
1. 導入済みNessus Agentのバージョンを確認してください。
2. 影響を受けるバージョンである場合、最新の修正済みバージョンへアップデートを適用してください。
■ 参考情報
- Tenable Security Advisory: https://www.tenable.com/security/tns-2026-01
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Nessus Agentの脆弱性に関する情報共有です。
■ 概要
Windows版Nessus Agentの「Nessus Agent Tray App」において、権限昇格が可能な脆弱性(CVE-2025-36640)が報告されました。インストール/アンインストール処理の不備を悪用し、特権昇格が行われる可能性があります。
■ 影響範囲
- Nessus Agent (Windows版) バージョン 10.9.3 未満
- Nessus Agent (Windows版) バージョン 11.0.0 ~ 11.0.2
■ 対応手順
1. 導入済みNessus Agentのバージョンを確認してください。
2. 影響を受けるバージョンである場合、最新の修正済みバージョンへアップデートを適用してください。
■ 参考情報
- Tenable Security Advisory: https://www.tenable.com/security/tns-2026-01
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Tenable Nessus Agent CVE-2025-36640
Dear IT/Security Team,
We are sharing information regarding a vulnerability in Tenable Nessus Agent.
■ Overview
A high-severity privilege escalation vulnerability (CVE-2025-36640) has been identified in the "Nessus Agent Tray App" for Windows. An attacker could potentially elevate privileges during the installation or uninstallation process.
■ Affected Scope
- Nessus Agent (Windows) versions prior to 10.9.3
- Nessus Agent (Windows) versions 11.0.0 to 11.0.2
■ Mitigation Steps
1. Verify the current version of Nessus Agent installed on Windows hosts.
2. Update the agent to the latest patched version as per the vendor's guidance.
■ Reference
- Tenable Security Advisory: https://www.tenable.com/security/tns-2026-01
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a vulnerability in Tenable Nessus Agent.
■ Overview
A high-severity privilege escalation vulnerability (CVE-2025-36640) has been identified in the "Nessus Agent Tray App" for Windows. An attacker could potentially elevate privileges during the installation or uninstallation process.
■ Affected Scope
- Nessus Agent (Windows) versions prior to 10.9.3
- Nessus Agent (Windows) versions 11.0.0 to 11.0.2
■ Mitigation Steps
1. Verify the current version of Nessus Agent installed on Windows hosts.
2. Update the agent to the latest patched version as per the vendor's guidance.
■ Reference
- Tenable Security Advisory: https://www.tenable.com/security/tns-2026-01
Priority: High
Deadline: Immediate