Falhas do tipo CWE-250

370 resultados

Execução com privilégios desnecessários

A aplicação ou processo executa com mais permissões (root, admin, service account privilegiado) do que realmente precisa para suas funções. Quando explorada, uma vulnerabilidade no código ganha acesso elevado, permitindo ao atacante comprometer todo o sistema ou dados sensíveis que só aquele nível de privilégio poderia acessar.

Exemplo

Um serviço web que apenas lê arquivos de configuração e envia emails roda como root. Uma injeção SQL nesse serviço não daria acesso apenas ao banco de dados, mas permitiria ao atacante criar usuários do SO, desabilitar firewalls ou acessar qualquer arquivo do servidor.

Como mitigar

Execute sempre com o menor nível de privilégio necessário — crie contas de serviço dedicadas e sem permissões administrativas. Revise regularmente as permissões de cada processo ou daemon em produção e remova acessos que não são estritamente usados.

CVE-2021-47700HIGHNagios XI < 5.8.7 Insecure Permissions on Highcharts Temporary DirectoryEPSS 0.3%CVE-2026-10843HIGHCloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on awsEPSS 0.3%CVE-2018-25123HIGHNagios XI < 5.5.7 Privilege Escalation via MRTG Graphing ComponentEPSS 0.3%CVE-2024-3498HIGHIncorrect Permission Assignment Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-22549MEDIUMBIG-IP Container Ingress Services vulnerabilityEPSS 0.3%CVE-2025-42943MEDIUMInformation Disclosure in SAP GUI for WindowsEPSS 0.3%CVE-2020-36868HIGHNagios XI < 5.7.3 Privilege escalation via Insecure getprofile.sh ScriptEPSS 0.3%CVE-2025-37128MEDIUMAuthenticated Arbitrary Process Termination allows potential System Disruption in ECOSEPSS 0.3%CVE-2025-56557CRITICALAn issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Matter protocol.EPSS 0.3%CVE-2023-0664HIGHA flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's WinEPSS 0.3%CVE-2022-1744MEDIUM2.2.6 EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250EPSS 0.3%CVE-2021-0204HIGHJunos OS: dexp Local Privilege Escalation vulnerabilities in SUID binariesEPSS 0.3%CVE-2022-27578An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated oEPSS 0.3%CVE-2025-0078HIGHIn main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to local escalation of privEPSS 0.3%CVE-2024-28140MEDIUMViolation of Least Privilege PrincipleEPSS 0.3%CVE-2026-4498HIGHExecution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scopeEPSS 0.3%CVE-2026-4606CRITICALGeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level PrivilegeEPSS 0.3%CVE-2026-87506HIGHPrivilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%CVE-2018-16888MEDIUMIt was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run froEPSS 0.3%CVE-2024-27110HIGHElevation of privilege vulnerability in GE HealthCare EchoPAC productsEPSS 0.3%