CVE-2014-2848 describes a race condition in the wmi_malware_scan.nbin plugin for Nessus 5.2.1, allowing local users to achieve privilege escalation. An attacker could replace the dissolvable agent executable in the Windows temporary directory with a malicious program during a specific time window. This vulnerability has a CVSS score of 6.9, indicating high severity due to complete confidentiality, integrity, and availability impacts, though it requires medium attack complexity and local access. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.1CPE matchmatch criteria | cpe:2.3:a:tenable:nessus:5.2.1:*:*:*:*:*:*:* | ||
<= 201402092115CPE matchmatch criteria | cpe:2.3:a:tenable:plugin-set:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.