Falhas do tipo CWE-277

71 resultados

Permissões Herdadas Inseguras

Ocorre quando um recurso (arquivo, diretório, chave de registro, objeto) herda permissões de seu container pai de forma insegura, deixando-o acessível a usuários ou processos não autorizados. O desenvolvedor assume que as permissões padrão do pai são adequadas, mas muitas vezes são excessivamente permissivas ou inadequadas para o contexto de segurança da aplicação.

Exemplo

Uma aplicação cria um arquivo de configuração com credenciais dentro de um diretório que herda permissões 'leitura para todos'. Qualquer usuário do sistema consegue ler o arquivo e extrair as credenciais, mesmo que o arquivo em si nunca tenha tido suas permissões explicitamente definidas.

Como mitigar

Sempre defina permissões explícitas no recurso criado, sem depender de herança. No código, use chamadas específicas de ACL (como chmod, SetFileSecurity no Windows ou APIs equivalentes) para garantir que apenas o proprietário ou processos autorizados tenham acesso, independente das permissões do diretório pai.

CVE-2023-45736MEDIUMInsecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enaEPSS 0.2%CVE-2025-32797MEDIUMConda-build Insecure Build Script Permissions Enabling Arbitrary Code ExecutionEPSS 0.2%CVE-2025-20008MEDIUMInsecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potEPSS 0.2%CVE-2022-41700MEDIUMInsecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticatEPSS 0.2%CVE-2023-33870MEDIUMInsecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enEPSS 0.2%CVE-2022-33898MEDIUMInsecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated EPSS 0.2%CVE-2023-28207MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plugEPSS 0.2%CVE-2023-33990HIGHDenial of Service (DoS) vulnerability in SAP SQL AnywhereEPSS 0.2%CVE-2024-21835MEDIUMInsecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable EPSS 0.2%CVE-2025-31332MEDIUMInsecure File permissions vulnerability in SAP BusinessObjects Business Intelligence PlatformEPSS 0.1%CVE-2024-51448MEDIUMIBM Robotic Process Automation privilege escalationEPSS 0.1%CVE-2022-38103MEDIUMInsecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated useEPSS 0.1%CVE-2022-41687MEDIUMInsecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.4EPSS 0.1%CVE-2022-46656MEDIUMInsecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentiallyEPSS 0.1%CVE-2022-41658MEDIUMInsecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentiaEPSS 0.1%CVE-2023-34391HIGHInsecure Inherited PermissionsEPSS 0.1%CVE-2022-36377MEDIUMInsecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before versioEPSS 0.1%CVE-2025-29982MEDIUMDell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker wEPSS 0.1%CVE-2025-3473MEDIUMIBM Security Guardium privilege escalationEPSS 0.1%CVE-2024-36276MEDIUMInsecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enableEPSS 0.1%