Falhas do tipo CWE-250

371 resultados

Execução com privilégios desnecessários

A aplicação ou processo executa com mais permissões (root, admin, service account privilegiado) do que realmente precisa para suas funções. Quando explorada, uma vulnerabilidade no código ganha acesso elevado, permitindo ao atacante comprometer todo o sistema ou dados sensíveis que só aquele nível de privilégio poderia acessar.

Exemplo

Um serviço web que apenas lê arquivos de configuração e envia emails roda como root. Uma injeção SQL nesse serviço não daria acesso apenas ao banco de dados, mas permitiria ao atacante criar usuários do SO, desabilitar firewalls ou acessar qualquer arquivo do servidor.

Como mitigar

Execute sempre com o menor nível de privilégio necessário — crie contas de serviço dedicadas e sem permissões administrativas. Revise regularmente as permissões de cada processo ou daemon em produção e remova acessos que não são estritamente usados.

CVE-2024-27146MEDIUMLack of privileges separationEPSS 0.2%CVE-2024-23299HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app EPSS 0.2%CVE-2026-54319MEDIUMDaytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escapeEPSS 0.2%CVE-2026-23528MEDIUMDask distributed Vulnerable to Remote Code Execution via Jupyter Proxy and DashboardEPSS 0.2%CVE-2021-36339HIGHThe Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulneEPSS 0.2%CVE-2026-17445HIGHIBM i is Affected By Improper Validation Vulnerability in Line Printer Daemon []EPSS 0.2%CVE-2023-33873HIGHAVEVA Operations Control Logger Execution with Unnecessary Privileges EPSS 0.2%CVE-2026-32673HIGHBIG-IP scripted monitor vulnerabilityEPSS 0.2%CVE-2026-50737CRITICALWhen applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressionsEPSS 0.2%CVE-2026-11167CRITICALInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised theEPSS 0.2%CVE-2021-27454The software performs an operation at a privilege level higher than the minimum level required, which creates new weaknesses or amplifies thEPSS 0.2%CVE-2024-49814HIGHIBM Security Verify Access Appliance Privilege EscalationEPSS 0.2%CVE-2021-27448A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versioEPSS 0.2%CVE-2021-34591HIGHBender Charge Controller: Local privilege EscalationEPSS 0.2%CVE-2022-34384HIGH Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | UpdaEPSS 0.2%CVE-2023-30997HIGHIBM Security Access Manager Docker privilege escalationEPSS 0.2%CVE-2023-30998HIGHIBM Security Access Manager Docker privilege escalationEPSS 0.2%CVE-2025-50505HIGHClash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default and exposes key functEPSS 0.2%CVE-2024-24245HIGHAn issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the EPSS 0.2%CVE-2024-27260HIGHIBM AIX command executionEPSS 0.2%