Falhas do tipo CWE-275

54 resultados

Problemas de Permissões

Fraqueza genérica que abrange falhas na configuração, verificação ou aplicação de permissões de acesso a recursos (arquivos, diretórios, APIs, dados). O software não valida adequadamente se o usuário tem direito de executar uma ação, permitindo acesso não autorizado a informações sensíveis ou operações críticas.

Exemplo

Um aplicativo web que lista arquivos de um usuário consultando diretamente o ID do arquivo na URL (ex: /arquivos/123) sem verificar se o usuário logado é o proprietário, permitindo que qualquer outro usuário autenticado acesse arquivos alheios.

Como mitigar

Implemente verificações explícitas de permissão antes de qualquer acesso a recursos (validar propriedade, grupo, role). Use modelos de controle de acesso bem definidos (RBAC, ABAC) e teste-os sistematicamente, incluindo testes de escalação de privilégio e acesso lateral.

CVE-2025-53168MEDIUMVulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this EPSS 0.1%CVE-2025-10941HIGHTopaz SERVCore Teller Installer SERVCoreTeller_2.0.40D.msi permissionEPSS 0.1%CVE-2026-28553MEDIUMVulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect sEPSS 0.1%CVE-2026-19190HIGHStableBit Scanner ScannerService Scanner.Service.exe permissionEPSS 0.1%CVE-2025-54618MEDIUMPermission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect serviEPSS 0.1%CVE-2026-19191HIGHStableBit DrivePool DrivePoolService DrivePool.Service.exe permissionEPSS 0.1%CVE-2026-12201MEDIUMIObit Malware Fighter DLL permissionEPSS 0.1%CVE-2025-58287HIGHUse After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.1%CVE-2026-41969MEDIUMPermission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may affect service confidenEPSS 0.1%CVE-2026-49311MEDIUMPermission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availabilEPSS 0.1%CVE-2022-0343LOWLocal Priviledge escalation in Perfetto Dev scriptsEPSS 0.1%CVE-2025-58288MEDIUMDenial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-41976MEDIUMPermission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%CVE-2026-41978MEDIUMPermission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect service confidentialiEPSS 0.1%