Falhas do tipo CWE-77

2.837 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2022-39086MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39085MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2023-20121MEDIUMCisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection VulnerabilitiesEPSS 0.2%CVE-2023-20122MEDIUMCisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection VulnerabilitiesEPSS 0.2%CVE-2024-46060HIGHAnaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directEPSS 0.2%CVE-2026-36365HIGHAn issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary EPSS 0.2%CVE-2024-46062HIGHMiniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home direcEPSS 0.2%CVE-2025-41721LOWSauter: Command InjectionEPSS 0.2%CVE-2024-33469HIGHAn issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate metEPSS 0.2%CVE-2026-73250MEDIUMNotepad++: Install-time PowerShell command injection through installation pathEPSS 0.2%CVE-2025-54564HIGHuploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution EPSS 0.2%CVE-2025-20117MEDIUMCisco Application Policy Infrastructure Controller Authenticated Command Injection VulnerabilityEPSS 0.2%CVE-2025-4089MEDIUMPotential local code execution in "copy as cURL" commandEPSS 0.2%CVE-2026-47242MEDIUMNet::IMAP: Command Injection via ID command argumentEPSS 0.2%CVE-2025-22237MEDIUMCVE-2025-22237 salt advisoryEPSS 0.2%CVE-2025-33249HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attackEPSS 0.2%CVE-2025-20278MEDIUMCisco Unified Communications Products Command Injection VulnerabilityEPSS 0.2%CVE-2026-75052LOWIn JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projectsEPSS 0.2%CVE-2026-21709MEDIUMA vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.EPSS 0.2%CVE-2025-27233MEDIUMZabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.EPSS 0.2%