Weaknesses of type CWE-250

371 results

Execução com Privilégios Desnecessários

Ocorre quando um processo ou aplicação executa com mais privilégios (permissões) do que realmente precisa para funcionar. Se o código é comprometido ou contém uma vulnerabilidade, o atacante herda todos esses privilégios elevados, ampliando drasticamente o dano possível.

Example

Um serviço web que processa uploads de arquivo rodando como root (ou SYSTEM no Windows) em vez de um usuário sem privilégios. Se a aplicação sofrer uma injeção de código, o atacante ganha controle total da máquina, não apenas do serviço.

How to mitigate

Execute aplicações com a menor quantidade de permissões necessária (princípio do menor privilégio): use contas de serviço dedicadas, separe componentes críticos, e aplique drop de privilégios após inicialização. Revise regularmente quais permissões cada processo realmente usa.

CVE-2025-22366HIGHMennekes smart/premium charges systems, Command injection in firmware upgradeEPSS 0.6%CVE-2025-22368HIGHMennekes smart/premium charges systems, Command injection in sCU firmware updateEPSS 0.6%CVE-2025-22367HIGHMennekes smart/premium charges systems, Command injection in time settingEPSS 0.6%CVE-2021-25653HIGHAvaya Aura Appliance Virtualization Platform Utilities Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-35783CRITICALA vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5EPSS 0.6%CVE-2022-38694HIGHIn BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution priviEPSS 0.6%CVE-2023-27313HIGHPrivilege Escalation Vulnerability in SnapCenterEPSS 0.6%CVE-2025-33108HIGHIBM Backup Recovery and Media Services for i code executionEPSS 0.6%CVE-2025-49581HIGHXWiki allows remote code execution through default value of wiki macro wiki-type parametersEPSS 0.6%CVE-2024-3330CRITICALSpotfire Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-1943HIGHPrivilege Escalation in kOps using GCE/GCP Provider in Gossip ModeEPSS 0.6%CVE-2025-6894MEDIUMAn Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the EPSS 0.6%CVE-2020-27826A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. ThiEPSS 0.6%CVE-2025-57119CRITICALAn issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login EPSS 0.6%CVE-2019-10168HIGHThe virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept EPSS 0.5%CVE-2026-18982HIGHOdh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/admin clusterrolesEPSS 0.5%CVE-2026-92574HIGHCri-o: cri-o checkpoint restore bypasses destination security contextEPSS 0.5%CVE-2024-21184HIGHVulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.2EPSS 0.5%CVE-2025-6949CRITICALAn Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical autEPSS 0.5%CVE-2019-15790LOWApport reads PID files with elevated privilegesEPSS 0.5%