Falhas do tipo CWE-250

370 resultados

Execução com privilégios desnecessários

A aplicação ou processo executa com mais permissões (root, admin, service account privilegiado) do que realmente precisa para suas funções. Quando explorada, uma vulnerabilidade no código ganha acesso elevado, permitindo ao atacante comprometer todo o sistema ou dados sensíveis que só aquele nível de privilégio poderia acessar.

Exemplo

Um serviço web que apenas lê arquivos de configuração e envia emails roda como root. Uma injeção SQL nesse serviço não daria acesso apenas ao banco de dados, mas permitiria ao atacante criar usuários do SO, desabilitar firewalls ou acessar qualquer arquivo do servidor.

Como mitigar

Execute sempre com o menor nível de privilégio necessário — crie contas de serviço dedicadas e sem permissões administrativas. Revise regularmente as permissões de cada processo ou daemon em produção e remova acessos que não são estritamente usados.

CVE-2025-22366HIGHMennekes smart/premium charges systems, Command injection in firmware upgradeEPSS 0.6%CVE-2025-22368HIGHMennekes smart/premium charges systems, Command injection in sCU firmware updateEPSS 0.6%CVE-2025-22367HIGHMennekes smart/premium charges systems, Command injection in time settingEPSS 0.6%CVE-2021-25653HIGHAvaya Aura Appliance Virtualization Platform Utilities Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-35783CRITICALA vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5EPSS 0.6%CVE-2022-38694HIGHIn BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution priviEPSS 0.6%CVE-2023-27313HIGHPrivilege Escalation Vulnerability in SnapCenterEPSS 0.6%CVE-2025-33108HIGHIBM Backup Recovery and Media Services for i code executionEPSS 0.6%CVE-2025-49581HIGHXWiki allows remote code execution through default value of wiki macro wiki-type parametersEPSS 0.6%CVE-2024-3330CRITICALSpotfire Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-1943HIGHPrivilege Escalation in kOps using GCE/GCP Provider in Gossip ModeEPSS 0.6%CVE-2025-6894MEDIUMAn Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the EPSS 0.6%CVE-2020-27826A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. ThiEPSS 0.6%CVE-2025-57119CRITICALAn issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login EPSS 0.6%CVE-2019-10168HIGHThe virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept EPSS 0.5%CVE-2026-18982HIGHOdh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/admin clusterrolesEPSS 0.5%CVE-2026-92574HIGHCri-o: cri-o checkpoint restore bypasses destination security contextEPSS 0.5%CVE-2024-21184HIGHVulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.2EPSS 0.5%CVE-2025-6949CRITICALAn Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical autEPSS 0.5%CVE-2019-15790LOWApport reads PID files with elevated privilegesEPSS 0.5%