Fallos del tipo CWE-269

2508 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2020-15934HIGHAn execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. mEPSS 0.2%CVE-2025-32955MEDIUMHarden-Runner Evasion of 'disable-sudo' policyEPSS 0.2%CVE-2026-21983HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2026-11108HIGHInappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalaEPSS 0.2%CVE-2023-52093HIGHAn exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affecteEPSS 0.2%CVE-2020-12615—An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and speciEPSS 0.2%CVE-2024-6677HIGHPrivilege escalation in uberAgentEPSS 0.2%CVE-2022-27677HIGH Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentialEPSS 0.2%CVE-2023-5847MEDIUM Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privilegEPSS 0.2%CVE-2024-36056MEDIUMHw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory via IOCTL 0x9c40649EPSS 0.2%CVE-2024-0049HIGHIn multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privileEPSS 0.2%CVE-2023-21512LOWImproper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notiEPSS 0.2%CVE-2025-43188HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gaEPSS 0.2%CVE-2024-33522MEDIUMPrivilege escalation in Calico CNI install binaryEPSS 0.2%CVE-2023-48418CRITICALUser Build misconfiguration resulting in local escalation of privilegeEPSS 0.2%CVE-2022-32900HIGHA logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be abEPSS 0.2%CVE-2024-21966HIGHA DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resultiEPSS 0.2%CVE-2025-53029LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2023-37925MEDIUMAn improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEEPSS 0.2%CVE-2025-43248HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may EPSS 0.2%