Weaknesses of type CWE-250

373 results

Execução com Privilégios Desnecessários

Ocorre quando um processo ou aplicação executa com mais privilégios (permissões) do que realmente precisa para funcionar. Se o código é comprometido ou contém uma vulnerabilidade, o atacante herda todos esses privilégios elevados, ampliando drasticamente o dano possível.

Example

Um serviço web que processa uploads de arquivo rodando como root (ou SYSTEM no Windows) em vez de um usuário sem privilégios. Se a aplicação sofrer uma injeção de código, o atacante ganha controle total da máquina, não apenas do serviço.

How to mitigate

Execute aplicações com a menor quantidade de permissões necessária (princípio do menor privilégio): use contas de serviço dedicadas, separe componentes críticos, e aplique drop de privilégios após inicialização. Revise regularmente quais permissões cada processo realmente usa.

CVE-2025-23180HIGHRibbon Communications - CWE-250: Execution with Unnecessary PrivilegesEPSS 0.3%CVE-2025-23181HIGHRibbon Communications - CWE-250: Execution with Unnecessary PrivilegesEPSS 0.3%CVE-2026-50566CRITICALFission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creationEPSS 0.3%CVE-2023-27247MEDIUMCynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling process privilege tokensEPSS 0.3%CVE-2026-25212CRITICALAn issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker withEPSS 0.3%CVE-2024-9473MEDIUMGlobalProtect App: Local Privilege Escalation (PE) VulnerabilityEPSS 0.3%CVE-2022-20676MEDIUMCisco IOS XE Software Tool Command Language Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-39261MEDIUMIn JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissionsEPSS 0.3%CVE-2023-37412MEDIUMIBM Aspera Faspex improper access controlEPSS 0.3%CVE-2024-20999HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Zones). The supported version that is affected is 11. Easily expEPSS 0.3%CVE-2024-34477HIGHconfigureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (becauseEPSS 0.3%CVE-2023-20217MEDIUMA vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local EPSS 0.3%CVE-2024-6834CRITICALImperative Local Command Injection allows Activity MaskingEPSS 0.3%CVE-2024-27147HIGHLocal Privilege Escalation and Remote Code Execution using snmpdEPSS 0.3%CVE-2024-25967MEDIUMDell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privilegeEPSS 0.3%CVE-2026-50565MEDIUMFission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder containerEPSS 0.3%CVE-2025-13911HIGHInductive Automation Ignition Execution with Unnecessary PrivilegesEPSS 0.3%CVE-2025-43017HIGHHP ThinPro 8.1 SP8 Security UpdatesEPSS 0.3%CVE-2021-1528HIGHCisco SD-WAN Software Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-0073HIGHCVEEPSS 0.2%