Falhas do tipo CWE-250

370 resultados

Execução com privilégios desnecessários

A aplicação ou processo executa com mais permissões (root, admin, service account privilegiado) do que realmente precisa para suas funções. Quando explorada, uma vulnerabilidade no código ganha acesso elevado, permitindo ao atacante comprometer todo o sistema ou dados sensíveis que só aquele nível de privilégio poderia acessar.

Exemplo

Um serviço web que apenas lê arquivos de configuração e envia emails roda como root. Uma injeção SQL nesse serviço não daria acesso apenas ao banco de dados, mas permitiria ao atacante criar usuários do SO, desabilitar firewalls ou acessar qualquer arquivo do servidor.

Como mitigar

Execute sempre com o menor nível de privilégio necessário — crie contas de serviço dedicadas e sem permissões administrativas. Revise regularmente as permissões de cada processo ou daemon em produção e remova acessos que não são estritamente usados.

CVE-2026-72654MEDIUMExecution with Unnecessary Privileges in Kibana Leading to Information DisclosureEPSS 0.4%CVE-2025-23009HIGHA local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arEPSS 0.4%CVE-2020-10056A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected applicationEPSS 0.4%CVE-2021-3100HIGHLog4j hot patch package privilege escalationEPSS 0.4%CVE-2018-8853Philips Brilliance CT devices operate user functions from within a contained kiosk in a Microsoft Windows operating system. Windows boots byEPSS 0.4%CVE-2024-23743LOWNotion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "thEPSS 0.4%CVE-2026-46618MEDIUMFission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executablesEPSS 0.4%CVE-2023-6006HIGHPrivilege Escalation VulnerabilityEPSS 0.4%CVE-2023-27312MEDIUMPrivilege Escalation Vulnerability in SnapCenter Plugin for VMware vSphere EPSS 0.4%CVE-2024-20420MEDIUMCisco ATA 190 Series Analog Telephone Adapter Firmware Privilege Escalation VulnerabilityEPSS 0.4%CVE-2020-10290MEDIUMRVD#1495: Universal Robots URCaps execute with unbounded privilegesEPSS 0.4%CVE-2025-23008HIGHAn improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low privileged attacker EPSS 0.4%CVE-2022-38691HIGHIn BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additionEPSS 0.3%CVE-2026-46617HIGHFission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap readEPSS 0.3%CVE-2019-10143MEDIUMIt was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who alreadEPSS 0.3%CVE-2023-38042HIGHA local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEMEPSS 0.3%CVE-2026-42088CRITICALOpenC3 COSMOS: Administrative Actions via the Script Runner ToolEPSS 0.3%CVE-2025-1977HIGHThe NPort 6100-G2/6200-G2 Series is affected by an execution with unnecessary privileges vulnerability (CVE-2025-1977) that allows an authenEPSS 0.3%CVE-2026-47190MEDIUMIPAM controller service account granted unnecessary full access to SecretsEPSS 0.3%CVE-2025-36137HIGHIBM Sterling Connect:Direct for UNIX command executionEPSS 0.3%