Fallos del tipo CWE-250

370 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2021-47700HIGHNagios XI < 5.8.7 Insecure Permissions on Highcharts Temporary DirectoryEPSS 0.3%CVE-2026-10843HIGHCloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on awsEPSS 0.3%CVE-2018-25123HIGHNagios XI < 5.5.7 Privilege Escalation via MRTG Graphing ComponentEPSS 0.3%CVE-2024-3498HIGHIncorrect Permission Assignment Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-22549MEDIUMBIG-IP Container Ingress Services vulnerabilityEPSS 0.3%CVE-2025-42943MEDIUMInformation Disclosure in SAP GUI for WindowsEPSS 0.3%CVE-2020-36868HIGHNagios XI < 5.7.3 Privilege escalation via Insecure getprofile.sh ScriptEPSS 0.3%CVE-2025-37128MEDIUMAuthenticated Arbitrary Process Termination allows potential System Disruption in ECOSEPSS 0.3%CVE-2025-56557CRITICALAn issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Matter protocol.EPSS 0.3%CVE-2023-0664HIGHA flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's WinEPSS 0.3%CVE-2022-1744MEDIUM2.2.6 EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250EPSS 0.3%CVE-2021-0204HIGHJunos OS: dexp Local Privilege Escalation vulnerabilities in SUID binariesEPSS 0.3%CVE-2022-27578An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated oEPSS 0.3%CVE-2025-0078HIGHIn main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to local escalation of privEPSS 0.3%CVE-2024-28140MEDIUMViolation of Least Privilege PrincipleEPSS 0.3%CVE-2026-4498HIGHExecution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scopeEPSS 0.3%CVE-2026-4606CRITICALGeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level PrivilegeEPSS 0.3%CVE-2026-87506HIGHPrivilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%CVE-2018-16888MEDIUMIt was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run froEPSS 0.3%CVE-2024-27110HIGHElevation of privilege vulnerability in GE HealthCare EchoPAC productsEPSS 0.3%