Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-21813HIGHExposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2025-24307LOWImproper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow aEPSS 0.2%CVE-2026-7977MEDIUMInappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a EPSS 0.2%CVE-2022-23455HIGHPotential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromEPSS 0.2%CVE-2025-27847MEDIUMIn ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.EPSS 0.2%CVE-2022-32931MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to EPSS 0.2%CVE-2025-27846MEDIUMIn ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOEPSS 0.2%CVE-2022-3369HIGHImproper handling of registry symbolic links in Bitdefender EnginesEPSS 0.2%CVE-2023-7241HIGHWebroot Antivirus COM-Hijacking LPEEPSS 0.2%CVE-2022-41975HIGHRealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.EPSS 0.2%CVE-2021-42082HIGHLocal Privilege Escalation to root in OSNEXUS QuantaStor before 6.0.0.355EPSS 0.2%CVE-2023-0221MEDIUMProduct security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypEPSS 0.2%CVE-2024-22106HIGHImproper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cauEPSS 0.2%CVE-2024-25088HIGHImproper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.EPSS 0.2%CVE-2024-21807CRITICALImproper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may EPSS 0.2%CVE-2026-12450MEDIUMInappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive infEPSS 0.2%CVE-2024-27357MEDIUMAn issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, andEPSS 0.2%CVE-2023-42952MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOEPSS 0.2%CVE-2025-36633HIGHLocal Privilege EscalationEPSS 0.2%CVE-2026-40001MEDIUMLocal privilege escalation vulnerability in ZTE PROCESS Guard service of the cloud computer clientEPSS 0.2%