Fallos del tipo CWE-250

370 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2026-72654MEDIUMExecution with Unnecessary Privileges in Kibana Leading to Information DisclosureEPSS 0.4%CVE-2025-23009HIGHA local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arEPSS 0.4%CVE-2020-10056A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected applicationEPSS 0.4%CVE-2021-3100HIGHLog4j hot patch package privilege escalationEPSS 0.4%CVE-2018-8853Philips Brilliance CT devices operate user functions from within a contained kiosk in a Microsoft Windows operating system. Windows boots byEPSS 0.4%CVE-2024-23743LOWNotion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "thEPSS 0.4%CVE-2026-46618MEDIUMFission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executablesEPSS 0.4%CVE-2023-6006HIGHPrivilege Escalation VulnerabilityEPSS 0.4%CVE-2023-27312MEDIUMPrivilege Escalation Vulnerability in SnapCenter Plugin for VMware vSphere EPSS 0.4%CVE-2024-20420MEDIUMCisco ATA 190 Series Analog Telephone Adapter Firmware Privilege Escalation VulnerabilityEPSS 0.4%CVE-2020-10290MEDIUMRVD#1495: Universal Robots URCaps execute with unbounded privilegesEPSS 0.4%CVE-2025-23008HIGHAn improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low privileged attacker EPSS 0.4%CVE-2022-38691HIGHIn BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additionEPSS 0.3%CVE-2026-46617HIGHFission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap readEPSS 0.3%CVE-2019-10143MEDIUMIt was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who alreadEPSS 0.3%CVE-2023-38042HIGHA local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEMEPSS 0.3%CVE-2026-42088CRITICALOpenC3 COSMOS: Administrative Actions via the Script Runner ToolEPSS 0.3%CVE-2025-1977HIGHThe NPort 6100-G2/6200-G2 Series is affected by an execution with unnecessary privileges vulnerability (CVE-2025-1977) that allows an authenEPSS 0.3%CVE-2026-47190MEDIUMIPAM controller service account granted unnecessary full access to SecretsEPSS 0.3%CVE-2025-36137HIGHIBM Sterling Connect:Direct for UNIX command executionEPSS 0.3%