Falhas do tipo CWE-268

22 resultados

Encadeamento de Privilégios

É quando um atacante combina múltiplas operações ou vulnerabilidades de baixo impacto individual para escalar gradualmente seus privilégios até ganhar acesso administrativo ou crítico. Cada passo sozinho pode parecer inofensivo, mas a sequência cria um caminho para comprometer o sistema.

Exemplo

Um usuário comum obtém acesso de leitura a um arquivo de configuração (passo 1), identifica credenciais fracas ali (passo 2), usa essas credenciais para acessar um serviço intermediário (passo 3), e por fim consegue executar comandos com privilégios de sistema. Nenhum passo isolado violaria política de segurança, mas juntos formam uma corrente de comprometimento.

Como mitigar

Aplique princípio do menor privilégio rigorosamente: nunca dê permissões desnecessárias, mesmo que pareçam inócuas. Monitore e audite sequências de ações suspeitas (tentativas de acesso a múltiplos recursos em padrão anormal), e segmente o acesso entre camadas do sistema para quebrar cadeias de ataque potenciais.

CVE-2025-49741HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 3.4%CVE-2019-3844MEDIUMIt was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, whichEPSS 0.9%CVE-2024-1250MEDIUMPrivilege Chaining in GitLabEPSS 0.5%CVE-2024-1299MEDIUMPrivilege Chaining in GitLabEPSS 0.5%CVE-2023-20194MEDIUMA vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operatinEPSS 0.5%CVE-2022-1003LOWSysadmin can override existing configs & bypass restrictions like EnableUploadsEPSS 0.5%CVE-2024-4877HIGHOpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI cEPSS 0.4%CVE-2025-36124MEDIUMIBM WebSphere Application Server Liberty bypass securityEPSS 0.4%CVE-2026-3888HIGHLocal Privilege Escalation in snapdEPSS 0.4%CVE-2023-0759MEDIUMPrivilege Chaining in cockpit-hq/cockpitEPSS 0.3%CVE-2023-5839HIGHPrivilege Chaining in hestiacp/hestiacpEPSS 0.3%CVE-2023-0971CRITICALCommand Authentication Bypass in Z/IP GatewayEPSS 0.3%CVE-2025-32955MEDIUMHarden-Runner Evasion of 'disable-sudo' policyEPSS 0.2%CVE-2023-2250MEDIUMA flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registrationEPSS 0.2%CVE-2025-0889HIGHPrivilege Management for Windows – Elevation of PrivilegeEPSS 0.2%CVE-2025-2903HIGHPrivilege Chaining in DelphixEPSS 0.2%CVE-2024-47045HIGHPrivilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepEPSS 0.1%CVE-2025-7973HIGHRockwell Automation FactoryTalk® ViewPoint Privilege Escalation VulnerabilityEPSS 0.1%CVE-2025-2297HIGHPrivilege Management for Windows - Elevation of PrivilegeEPSS 0.1%CVE-2025-20112MEDIUMCisco Unified Communications Products Privilege Escalation VulnerabilityEPSS 0.1%