Fallos del tipo CWE-250

370 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2025-22366HIGHMennekes smart/premium charges systems, Command injection in firmware upgradeEPSS 0.6%CVE-2025-22368HIGHMennekes smart/premium charges systems, Command injection in sCU firmware updateEPSS 0.6%CVE-2025-22367HIGHMennekes smart/premium charges systems, Command injection in time settingEPSS 0.6%CVE-2021-25653HIGHAvaya Aura Appliance Virtualization Platform Utilities Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-35783CRITICALA vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5EPSS 0.6%CVE-2022-38694HIGHIn BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution priviEPSS 0.6%CVE-2023-27313HIGHPrivilege Escalation Vulnerability in SnapCenterEPSS 0.6%CVE-2025-33108HIGHIBM Backup Recovery and Media Services for i code executionEPSS 0.6%CVE-2025-49581HIGHXWiki allows remote code execution through default value of wiki macro wiki-type parametersEPSS 0.6%CVE-2024-3330CRITICALSpotfire Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-1943HIGHPrivilege Escalation in kOps using GCE/GCP Provider in Gossip ModeEPSS 0.6%CVE-2025-6894MEDIUMAn Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the EPSS 0.6%CVE-2020-27826A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. ThiEPSS 0.6%CVE-2025-57119CRITICALAn issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login EPSS 0.6%CVE-2019-10168HIGHThe virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept EPSS 0.5%CVE-2026-18982HIGHOdh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/admin clusterrolesEPSS 0.5%CVE-2026-92574HIGHCri-o: cri-o checkpoint restore bypasses destination security contextEPSS 0.5%CVE-2024-21184HIGHVulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.2EPSS 0.5%CVE-2025-6949CRITICALAn Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical autEPSS 0.5%CVE-2019-15790LOWApport reads PID files with elevated privilegesEPSS 0.5%