Fallos del tipo CWE-272

41 resultados

Violação do Princípio de Menor Privilégio

Ocorre quando um processo, aplicação ou usuário opera com mais permissões do que o necessário para executar sua função. Se esse componente for comprometido, o atacante herda todos esses privilégios extras, ampliando o dano possível. É uma fraqueza de design que ignora a compartimentalização de segurança.

Ejemplo

Um serviço web que lê arquivos de log executa como root ao invés de um usuário restrito. Quando explorada uma vulnerabilidade remota no servidor, o atacante ganha acesso root imediato, em vez de estar confinado às permissões de um usuário comum.

Cómo mitigar

Execute processos e aplicações com o menor conjunto de permissões viável para suas funções. Use contas de serviço dedicadas com privilégios mínimos, implemente controle de acesso granular (ACL) e aplique técnicas como sandboxing ou containers com capabilities reduzidas. Revise periodicamente quais permissões cada componente realmente precisa.

CVE-2025-1384HIGHLeast Privilege Violation Vulnerability in the communications functions of NJ/NX-series Machine Automation ControllersEPSS 0.2%CVE-2024-27165HIGHLocal Privilege EscalationEPSS 0.2%CVE-2026-11494MEDIUMTOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violationEPSS 0.2%CVE-2025-68267MEDIUMIn JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installaEPSS 0.2%CVE-2026-11554MEDIUMTOTOLINK CP450 vsftpd vsftpd.conf least privilege violationEPSS 0.2%CVE-2024-0638HIGHPrivilege escalation in mk_oracle pluginsEPSS 0.2%CVE-2024-28824HIGHPrivilege escalation in mk_informix pluginEPSS 0.2%CVE-2026-35535HIGHIn Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailerEPSS 0.2%CVE-2024-28829MEDIUMPrivilege escalation in mk_informix pluginEPSS 0.2%CVE-2025-47809HIGHWibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitatiEPSS 0.2%CVE-2023-28047HIGH Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local loEPSS 0.2%CVE-2025-8758HIGHTRENDnet TEW-822DRE vsftpd least privilege violationEPSS 0.2%CVE-2023-32451HIGH Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during instEPSS 0.2%CVE-2025-8757HIGHTRENDnet TV-IP110WN Embedded Boa Web Server boa.conf least privilege violationEPSS 0.2%CVE-2023-28046MEDIUM Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during uninstallation A local lEPSS 0.1%CVE-2026-59915HIGHDell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacEPSS 0.1%CVE-2025-9711HIGHPrivilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2bEPSS 0.1%CVE-2026-79693LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege ViEPSS 0.1%CVE-2026-79944LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege ViEPSS 0.1%CVE-2026-32655MEDIUMDell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attackEPSS 0.1%