Falhas do tipo CWE-250

370 resultados

Execução com privilégios desnecessários

A aplicação ou processo executa com mais permissões (root, admin, service account privilegiado) do que realmente precisa para suas funções. Quando explorada, uma vulnerabilidade no código ganha acesso elevado, permitindo ao atacante comprometer todo o sistema ou dados sensíveis que só aquele nível de privilégio poderia acessar.

Exemplo

Um serviço web que apenas lê arquivos de configuração e envia emails roda como root. Uma injeção SQL nesse serviço não daria acesso apenas ao banco de dados, mas permitiria ao atacante criar usuários do SO, desabilitar firewalls ou acessar qualquer arquivo do servidor.

Como mitigar

Execute sempre com o menor nível de privilégio necessário — crie contas de serviço dedicadas e sem permissões administrativas. Revise regularmente as permissões de cada processo ou daemon em produção e remova acessos que não são estritamente usados.

CVE-2025-23181HIGHRibbon Communications - CWE-250: Execution with Unnecessary PrivilegesEPSS 0.3%CVE-2025-23180HIGHRibbon Communications - CWE-250: Execution with Unnecessary PrivilegesEPSS 0.3%CVE-2026-50566CRITICALFission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creationEPSS 0.3%CVE-2026-25212CRITICALAn issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker withEPSS 0.3%CVE-2023-27247MEDIUMCynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling process privilege tokensEPSS 0.3%CVE-2024-9473MEDIUMGlobalProtect App: Local Privilege Escalation (PE) VulnerabilityEPSS 0.3%CVE-2022-20676MEDIUMCisco IOS XE Software Tool Command Language Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-39261MEDIUMIn JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissionsEPSS 0.3%CVE-2024-20999HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Zones). The supported version that is affected is 11. Easily expEPSS 0.3%CVE-2023-37412MEDIUMIBM Aspera Faspex improper access controlEPSS 0.3%CVE-2023-20217MEDIUMA vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local EPSS 0.3%CVE-2024-34477HIGHconfigureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (becauseEPSS 0.3%CVE-2024-6834CRITICALImperative Local Command Injection allows Activity MaskingEPSS 0.3%CVE-2024-27147HIGHLocal Privilege Escalation and Remote Code Execution using snmpdEPSS 0.3%CVE-2024-25967MEDIUMDell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privilegeEPSS 0.3%CVE-2026-50565MEDIUMFission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder containerEPSS 0.3%CVE-2025-13911HIGHInductive Automation Ignition Execution with Unnecessary PrivilegesEPSS 0.3%CVE-2025-43017HIGHHP ThinPro 8.1 SP8 Security UpdatesEPSS 0.3%CVE-2021-1528HIGHCisco SD-WAN Software Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-0073HIGHCVEEPSS 0.2%