Vulnerabilities · 5h ago

Tenable patch closes a path to domain controller SYSTEM

INCIBE-CERT says Takumi Ito reported a critical flaw in Tenable Identity Exposure SaaS 3.125.0 and earlier that can let an authenticated user with limited rights run arbitrary commands as SYSTEM on the domain controller holding the PDC Emulator role. CSIRT Italia and ACN both issued security updates for the same issue.

The bug is in Active Directory Events Listener: specially crafted input can steer the listener into executing attacker-chosen commands, so the break is not confined to the SaaS console. Because the target is a domain controller, a low-privileged account can be promoted into control of the identity core behind Active Directory.

For teams that use Tenable to manage identity data, the exposure sits where the product meets the domain, not inside a cloud management plane. If that listener can influence code execution on a PDC Emulator host, the downstream risk is domain-wide privilege escalation, even after the SaaS side is updated.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-10-09

Editions

Related stories