Fallos del tipo CWE-250

370 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2022-44544CRITICALMahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger EPSS 0.8%CVE-2025-33224CRITICALNVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploiEPSS 0.8%CVE-2019-16767MEDIUMIn EzMaster before 5.2.11 docker containers were executed with advanced privileges by defaultEPSS 0.8%CVE-2025-32445CRITICALUsers can gain privileged access to the host system and cluster with EventSource and Sensor CREPSS 0.8%CVE-2022-32535MEDIUMWeb server runs as rootEPSS 0.8%CVE-2018-1087HIGHkernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in theEPSS 0.8%CVE-2026-42833CRITICALMicrosoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-20478MEDIUMCisco Application Policy Infrastructure Controller App Privilege Escalation VulnerabilityEPSS 0.7%CVE-2020-26278MEDIUMWeave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilitiesEPSS 0.7%CVE-2024-28139HIGHPrivilege escalation through sudo misconfigurationEPSS 0.7%CVE-2023-45592MEDIUMA CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the EPSS 0.7%CVE-2024-48013HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecessary Privileges vulneEPSS 0.7%CVE-2019-16784HIGHLocal Privilege Escalation present only on the Windows version of PyInstallerEPSS 0.7%CVE-2025-33223CRITICALNVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploiEPSS 0.7%CVE-2025-42958CRITICALMissing Authentication check in SAP NetWeaverEPSS 0.7%CVE-2025-6893CRITICALAn Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in brokEPSS 0.7%CVE-2026-27208CRITICALapi-gateway-deploy Affected by Exploitable Command Injection via Unprivileged Root ExecutionEPSS 0.7%CVE-2022-21699HIGHExecution with Unnecessary Privileges in ipythonEPSS 0.7%CVE-2025-22366HIGHMennekes smart/premium charges systems, Command injection in firmware upgradeEPSS 0.6%CVE-2025-22368HIGHMennekes smart/premium charges systems, Command injection in sCU firmware updateEPSS 0.6%