Fallos del tipo CWE-250

371 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2024-27146MEDIUMLack of privileges separationEPSS 0.2%CVE-2024-23299HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app EPSS 0.2%CVE-2026-54319MEDIUMDaytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escapeEPSS 0.2%CVE-2026-23528MEDIUMDask distributed Vulnerable to Remote Code Execution via Jupyter Proxy and DashboardEPSS 0.2%CVE-2021-36339HIGHThe Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulneEPSS 0.2%CVE-2026-17445HIGHIBM i is Affected By Improper Validation Vulnerability in Line Printer Daemon []EPSS 0.2%CVE-2023-33873HIGHAVEVA Operations Control Logger Execution with Unnecessary Privileges EPSS 0.2%CVE-2026-32673HIGHBIG-IP scripted monitor vulnerabilityEPSS 0.2%CVE-2026-50737CRITICALWhen applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressionsEPSS 0.2%CVE-2026-11167CRITICALInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised theEPSS 0.2%CVE-2021-27454The software performs an operation at a privilege level higher than the minimum level required, which creates new weaknesses or amplifies thEPSS 0.2%CVE-2024-49814HIGHIBM Security Verify Access Appliance Privilege EscalationEPSS 0.2%CVE-2021-27448A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versioEPSS 0.2%CVE-2021-34591HIGHBender Charge Controller: Local privilege EscalationEPSS 0.2%CVE-2022-34384HIGH Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | UpdaEPSS 0.2%CVE-2023-30997HIGHIBM Security Access Manager Docker privilege escalationEPSS 0.2%CVE-2023-30998HIGHIBM Security Access Manager Docker privilege escalationEPSS 0.2%CVE-2025-50505HIGHClash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default and exposes key functEPSS 0.2%CVE-2024-24245HIGHAn issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the EPSS 0.2%CVE-2024-27260HIGHIBM AIX command executionEPSS 0.2%