Weaknesses of type CWE-250

373 results

Execução com Privilégios Desnecessários

Ocorre quando um processo ou aplicação executa com mais privilégios (permissões) do que realmente precisa para funcionar. Se o código é comprometido ou contém uma vulnerabilidade, o atacante herda todos esses privilégios elevados, ampliando drasticamente o dano possível.

Example

Um serviço web que processa uploads de arquivo rodando como root (ou SYSTEM no Windows) em vez de um usuário sem privilégios. Se a aplicação sofrer uma injeção de código, o atacante ganha controle total da máquina, não apenas do serviço.

How to mitigate

Execute aplicações com a menor quantidade de permissões necessária (princípio do menor privilégio): use contas de serviço dedicadas, separe componentes críticos, e aplique drop de privilégios após inicialização. Revise regularmente quais permissões cada processo realmente usa.

CVE-2024-27146MEDIUMLack of privileges separationEPSS 0.2%CVE-2026-54319MEDIUMDaytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escapeEPSS 0.2%CVE-2024-23299HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app EPSS 0.2%CVE-2026-23528MEDIUMDask distributed Vulnerable to Remote Code Execution via Jupyter Proxy and DashboardEPSS 0.2%CVE-2021-36339HIGHThe Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulneEPSS 0.2%CVE-2026-17445HIGHIBM i is Affected By Improper Validation Vulnerability in Line Printer Daemon []EPSS 0.2%CVE-2023-33873HIGHAVEVA Operations Control Logger Execution with Unnecessary Privileges EPSS 0.2%CVE-2026-32673HIGHBIG-IP scripted monitor vulnerabilityEPSS 0.2%CVE-2026-50737CRITICALWhen applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressionsEPSS 0.2%CVE-2026-11167CRITICALInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised theEPSS 0.2%CVE-2021-27454—The software performs an operation at a privilege level higher than the minimum level required, which creates new weaknesses or amplifies thEPSS 0.2%CVE-2021-27448—A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versioEPSS 0.2%CVE-2024-49814HIGHIBM Security Verify Access Appliance Privilege EscalationEPSS 0.2%CVE-2021-34591HIGHBender Charge Controller: Local privilege EscalationEPSS 0.2%CVE-2022-34384HIGH Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | UpdaEPSS 0.2%CVE-2023-30998HIGHIBM Security Access Manager Docker privilege escalationEPSS 0.2%CVE-2025-50505HIGHClash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default and exposes key functEPSS 0.2%CVE-2023-30997HIGHIBM Security Access Manager Docker privilege escalationEPSS 0.2%CVE-2024-24245HIGHAn issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the EPSS 0.2%CVE-2024-27260HIGHIBM AIX command executionEPSS 0.2%