Tenable patch closes a path to domain controller SYSTEM
INCIBE-CERT says Takumi Ito reported a critical flaw in Tenable Identity Exposure SaaS 3.125.0 and earlier that can let an authenticated user with limited rights run arbitrary commands as SYSTEM on the domain controller holding the PDC Emulator role. CSIRT Italia and ACN both issued security updates for the same issue.
The bug is in Active Directory Events Listener: specially crafted input can steer the listener into executing attacker-chosen commands, so the break is not confined to the SaaS console. Because the target is a domain controller, a low-privileged account can be promoted into control of the identity core behind Active Directory.
For teams that use Tenable to manage identity data, the exposure sits where the product meets the domain, not inside a cloud management plane. If that listener can influence code execution on a PDC Emulator host, the downstream risk is domain-wide privilege escalation, even after the SaaS side is updated.
Rilasciati aggiornamenti di sicurezza che risolvono una vulnerabilità con gravità "critica" in Tenable Identity Exposure (SaaS), soluzione cloud per la gestione delle identità in ambienti Microsoft Active Directory e Entra ID.