Falhas do tipo CWE-250

370 resultados

Execução com privilégios desnecessários

A aplicação ou processo executa com mais permissões (root, admin, service account privilegiado) do que realmente precisa para suas funções. Quando explorada, uma vulnerabilidade no código ganha acesso elevado, permitindo ao atacante comprometer todo o sistema ou dados sensíveis que só aquele nível de privilégio poderia acessar.

Exemplo

Um serviço web que apenas lê arquivos de configuração e envia emails roda como root. Uma injeção SQL nesse serviço não daria acesso apenas ao banco de dados, mas permitiria ao atacante criar usuários do SO, desabilitar firewalls ou acessar qualquer arquivo do servidor.

Como mitigar

Execute sempre com o menor nível de privilégio necessário — crie contas de serviço dedicadas e sem permissões administrativas. Revise regularmente as permissões de cada processo ou daemon em produção e remova acessos que não são estritamente usados.

CVE-2023-4662CRITICALRCE in Saphira ConnectEPSS 1.1%CVE-2018-10892MEDIUMThe default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw alloEPSS 1.1%CVE-2024-27143CRITICALPre-authenticated Remote Code ExecutionEPSS 1.1%CVE-2023-5207HIGHExecution with Unnecessary Privileges in GitLabEPSS 1.1%CVE-2022-43553HIGHA remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account EPSS 1.1%CVE-2025-5196HIGHWing FTP Server Lua Admin Console unnecessary privilegesEPSS 1.0%CVE-2023-27010HIGHWondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability allows attackers to escEPSS 1.0%CVE-2021-3576HIGHPrivilege escalation via SeImpersonatePrivilegeEPSS 1.0%CVE-2022-2634CRITICALDigi ConnectPort X2DEPSS 1.0%CVE-2026-69409MEDIUMMicrosoft Office SharePoint Information Disclosure VulnerabilityEPSS 1.0%CVE-2026-59133HIGHMicrosoft High Performance Computing (HPC) Pack Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-32080CRITICALWings vulnerable to escape to host from installation containerEPSS 0.9%CVE-2023-1966HIGHCVE-2023-1966EPSS 0.9%CVE-2022-40182A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 0.9%CVE-2026-69464HIGHMicrosoft Office SharePoint Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-48584CRITICALMicrosoft Azure Synapse Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-41900HIGHOpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution EnvironmentEPSS 0.9%CVE-2024-22017HIGHsetuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to performEPSS 0.9%CVE-2024-21003LOWVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions thEPSS 0.9%CVE-2018-10856MEDIUMIt has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This resulEPSS 0.8%