Fallos del tipo CWE-250

370 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2026-44477CRITICALCloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCEEPSS 0.5%CVE-2026-72508CRITICALMulticloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)EPSS 0.5%CVE-2024-8767CRITICALSensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup pluEPSS 0.5%CVE-2019-10145HIGHrkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` do not havEPSS 0.5%CVE-2023-4003HIGH One Identity Password Manager version 5.9.7.1 - Unauthenticated physical access privilege escalationEPSS 0.5%CVE-2019-10144HIGHrkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given EPSS 0.5%CVE-2018-10853HIGHA flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not checkEPSS 0.5%CVE-2025-6019HIGHLibblockdev: lpe from allow_active to root in libblockdev via udisksEPSS 0.5%CVE-2018-10872MEDIUMA flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. EPSS 0.5%CVE-2019-10147MEDIUMrkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are not liEPSS 0.5%CVE-2023-43018MEDIUMIBM CICS TX privilege escalationEPSS 0.4%CVE-2023-42954MEDIUMA privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in toEPSS 0.4%CVE-2024-8266MEDIUMExecution with Unnecessary Privileges in GitLabEPSS 0.4%CVE-2024-7102CRITICALExecution with Unnecessary Privileges in GitLabEPSS 0.4%CVE-2025-33103HIGHIBM i privilege escalationEPSS 0.4%CVE-2026-70496CRITICALSearch-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestworkEPSS 0.4%CVE-2023-31175HIGHExecution with Unnecessary PrivilegesEPSS 0.4%CVE-2026-34877CRITICALAn issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or sEPSS 0.4%CVE-2026-15584HIGHRedhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node rootEPSS 0.4%CVE-2026-30225MEDIUMOliveTin: RestartAction always runs actions as guestEPSS 0.4%