Fallos del tipo CWE-281

225 resultados

Preservação inadequada de permissões

É quando um sistema copia, move ou cria arquivos, diretórios ou outros recursos sem manter ou validar corretamente as permissões originais, resultando em acesso indevido. Um atacante pode ganhar acesso a dados sensíveis ou executar operações que não deveria poder fazer porque as permissões foram perdidas, relaxadas ou não propagadas corretamente.

Ejemplo

Um backup automático copia arquivos de um diretório protegido (modo 600) para uma pasta temporária, mas o processo não preserva as permissões originais. Os arquivos acabam com permissões padrão (644), permitindo que qualquer usuário do sistema leia dados sensíveis que deveriam ser privados.

Cómo mitigar

Ao copiar, mover ou criar recursos, sempre preserve explicitamente as permissões originais usando APIs que suportam isso (como `cp -p`, `shutil.copystat()` em Python, ou equivalentes). Valide permissões antes e depois da operação e teste cenários onde dados sensíveis são envolvidos.

CVE-2026-24194HIGHNVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handliEPSS 0.2%CVE-2025-24791MEDIUMsnowflake-connector-nodejs has incorrect validation of temporary credential cache file permissionsEPSS 0.1%CVE-2022-26024MEDIUMImproper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may alloEPSS 0.1%CVE-2023-21464MEDIUMImproper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attackeEPSS 0.1%CVE-2024-21816MEDIUMBackground task manager has an improper preservation of permissions vulnerabilityEPSS 0.1%CVE-2026-35361LOWuutils coreutils mknod Security Label Inconsistency and Broken Cleanup on SELinux SystemsEPSS 0.1%CVE-2024-22177LOWAudio has an improper preservation of permissions vulnerabilityEPSS 0.1%CVE-2026-23556CRITICALoxenstored keeps quota related use counts across domain destructionEPSS 0.1%CVE-2026-82964HIGHAvast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx.sysEPSS 0.1%CVE-2025-43026HIGHHP Support Assistant – Potential Escalation of PrivilegeEPSS 0.1%CVE-2025-37735HIGHImproper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the DefenEPSS 0.1%CVE-2026-35351MEDIUMuutils coreutils mv Silent Ownership Loss in Cross-Device OperationsEPSS 0.1%CVE-2025-27247MEDIUMPasteboard has an improper preservation of permissions vulnerabilityEPSS 0.1%CVE-2025-26691MEDIUMtelephony_call_manager has an improper preservation of permissions vulnerabilityEPSS 0.1%CVE-2025-27563LOWsecurity_access_token has an improper preservation of permissions vulnerabilityEPSS 0.1%CVE-2026-35350MEDIUMuutils coreutils cp Unexpected Privileged Executable Creation with -pEPSS 0.1%CVE-2025-26693LOWsecurity_access_token has an improper preservation of permissions vulnerabilityEPSS 0.1%CVE-2024-29080MEDIUMPotential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software DrivEPSS 0.1%CVE-2026-25850MEDIUMfilemanagement_storage_service has an improper preservation of permissions vulnerabilityEPSS 0.1%CVE-2025-69875HIGHA vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore pEPSS 0.1%