Weaknesses of type CWE-250

373 results

Execução com Privilégios Desnecessários

Ocorre quando um processo ou aplicação executa com mais privilégios (permissões) do que realmente precisa para funcionar. Se o código é comprometido ou contém uma vulnerabilidade, o atacante herda todos esses privilégios elevados, ampliando drasticamente o dano possível.

Example

Um serviço web que processa uploads de arquivo rodando como root (ou SYSTEM no Windows) em vez de um usuário sem privilégios. Se a aplicação sofrer uma injeção de código, o atacante ganha controle total da máquina, não apenas do serviço.

How to mitigate

Execute aplicações com a menor quantidade de permissões necessária (princípio do menor privilégio): use contas de serviço dedicadas, separe componentes críticos, e aplique drop de privilégios após inicialização. Revise regularmente quais permissões cada processo realmente usa.

CVE-2024-6030HIGHTesla Model S oFono Unnecessary Privileges Sandbox Escape VulnerabilityEPSS 0.2%CVE-2026-13104HIGHA potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authentiEPSS 0.2%CVE-2024-20435HIGHA vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commaEPSS 0.2%CVE-2025-8907HIGHH3C M2 NAS Webserver Configuration unnecessary privilegesEPSS 0.2%CVE-2025-0120HIGHGlobalProtect App: Local Privilege Escalation (PE) VulnerabilityEPSS 0.2%CVE-2026-20017MEDIUMCisco Secure FTD Software Authenticated Command Injection VulnerabilityEPSS 0.2%CVE-2024-32853MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privilegeEPSS 0.2%CVE-2026-33793HIGHJunos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the systemEPSS 0.2%CVE-2025-40942HIGHA vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege eEPSS 0.2%CVE-2024-31891HIGHIBM Storage Scale privilege escalationEPSS 0.2%CVE-2025-69783HIGHA local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.gEPSS 0.2%CVE-2026-12505HIGHCifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcallEPSS 0.2%CVE-2026-32643HIGHBIG-IP and BIG-IQ privilege escalation vulnerabilityEPSS 0.2%CVE-2025-8486HIGHA potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.EPSS 0.2%CVE-2025-33120HIGHIBM QRadar SIEM privilege escalationEPSS 0.2%CVE-2026-15226HIGHsnapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp TemplatesEPSS 0.2%CVE-2023-4814HIGH A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for wEPSS 0.2%CVE-2025-50753HIGHMitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "deviceinfo show file" isEPSS 0.2%CVE-2026-25740MEDIUMPrivilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS moduleEPSS 0.2%CVE-2025-10885HIGHPrivilege Escalation VulnerabilityEPSS 0.2%