Falhas do tipo CWE-250

368 resultados

Execução com privilégios desnecessários

A aplicação ou processo executa com mais permissões (root, admin, service account privilegiado) do que realmente precisa para suas funções. Quando explorada, uma vulnerabilidade no código ganha acesso elevado, permitindo ao atacante comprometer todo o sistema ou dados sensíveis que só aquele nível de privilégio poderia acessar.

Exemplo

Um serviço web que apenas lê arquivos de configuração e envia emails roda como root. Uma injeção SQL nesse serviço não daria acesso apenas ao banco de dados, mas permitiria ao atacante criar usuários do SO, desabilitar firewalls ou acessar qualquer arquivo do servidor.

Como mitigar

Execute sempre com o menor nível de privilégio necessário — crie contas de serviço dedicadas e sem permissões administrativas. Revise regularmente as permissões de cada processo ou daemon em produção e remova acessos que não são estritamente usados.

CVE-2022-44544CRITICALMahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger EPSS 0.8%CVE-2025-33224CRITICALNVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploiEPSS 0.8%CVE-2019-16767MEDIUMIn EzMaster before 5.2.11 docker containers were executed with advanced privileges by defaultEPSS 0.8%CVE-2025-32445CRITICALUsers can gain privileged access to the host system and cluster with EventSource and Sensor CREPSS 0.8%CVE-2022-32535MEDIUMWeb server runs as rootEPSS 0.8%CVE-2018-1087HIGHkernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in theEPSS 0.8%CVE-2026-42833CRITICALMicrosoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-20478MEDIUMCisco Application Policy Infrastructure Controller App Privilege Escalation VulnerabilityEPSS 0.7%CVE-2020-26278MEDIUMWeave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilitiesEPSS 0.7%CVE-2024-28139HIGHPrivilege escalation through sudo misconfigurationEPSS 0.7%CVE-2023-45592MEDIUMA CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the EPSS 0.7%CVE-2024-48013HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecessary Privileges vulneEPSS 0.7%CVE-2019-16784HIGHLocal Privilege Escalation present only on the Windows version of PyInstallerEPSS 0.7%CVE-2025-33223CRITICALNVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploiEPSS 0.7%CVE-2025-42958CRITICALMissing Authentication check in SAP NetWeaverEPSS 0.7%CVE-2017-7518MEDIUMA flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulatioEPSS 0.7%CVE-2025-6893CRITICALAn Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in brokEPSS 0.7%CVE-2026-27208CRITICALapi-gateway-deploy Affected by Exploitable Command Injection via Unprivileged Root ExecutionEPSS 0.7%CVE-2022-21699HIGHExecution with Unnecessary Privileges in ipythonEPSS 0.7%CVE-2025-22367HIGHMennekes smart/premium charges systems, Command injection in time settingEPSS 0.6%