Fallos del tipo CWE-250

372 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2026-23559CRITICALMultiple RBAC issues in XAPIEPSS 0.2%CVE-2026-13104HIGHA potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authentiEPSS 0.2%CVE-2024-20435HIGHA vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commaEPSS 0.2%CVE-2025-8907HIGHH3C M2 NAS Webserver Configuration unnecessary privilegesEPSS 0.2%CVE-2025-0120HIGHGlobalProtect App: Local Privilege Escalation (PE) VulnerabilityEPSS 0.2%CVE-2026-20017MEDIUMCisco Secure FTD Software Authenticated Command Injection VulnerabilityEPSS 0.2%CVE-2024-32853MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privilegeEPSS 0.2%CVE-2026-33793HIGHJunos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the systemEPSS 0.2%CVE-2025-40942HIGHA vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege eEPSS 0.2%CVE-2025-69783HIGHA local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.gEPSS 0.2%CVE-2024-31891HIGHIBM Storage Scale privilege escalationEPSS 0.2%CVE-2026-12505HIGHCifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcallEPSS 0.2%CVE-2026-32643HIGHBIG-IP and BIG-IQ privilege escalation vulnerabilityEPSS 0.2%CVE-2025-8486HIGHA potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.EPSS 0.2%CVE-2025-33120HIGHIBM QRadar SIEM privilege escalationEPSS 0.2%CVE-2023-4814HIGH A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for wEPSS 0.2%CVE-2026-25740MEDIUMPrivilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS moduleEPSS 0.2%CVE-2025-50753HIGHMitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "deviceinfo show file" isEPSS 0.2%CVE-2026-15226HIGHsnapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp TemplatesEPSS 0.2%CVE-2025-10885HIGHPrivilege Escalation VulnerabilityEPSS 0.2%