VYPR

CWE-250

Execution with Unnecessary Privileges

BaseDraftLikelihood: Medium

Description

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-470 · CAPEC-69

CVEs mapped to this weakness (358)

page 13 of 18
  • CVE-2024-6030HigApr 30, 2025
    risk 0.46cvss 7.0epss 0.00

    Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code within the sandbox on the target system in order…

  • CVE-2025-0120HigApr 11, 2025
    risk 0.46cvss 7.0epss 0.00

    A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local…

  • CVE-2024-52799HigNov 21, 2024
    risk 0.46cvss 8.2epss 0.00

    Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workflow-role has excessive privileges, the worst being create pods/exec, which will allow kubectl exec into any Pod in the same namespace, i.e. arbitrary code…

  • CVE-2023-4814HigSep 14, 2023
    risk 0.46cvss 7.1epss 0.00

    A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to.

  • CVE-2022-21699HigJan 19, 2022
    risk 0.46cvss 8.2epss 0.01

    IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing…

  • CVE-2026-40550MedApr 28, 2026
    risk 0.45cvss epss 0.00

    mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running application instance connected to the backend server can extract database credentials from the…

  • CVE-2026-40638MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

  • CVE-2026-25908MedApr 27, 2026
    risk 0.44cvss 6.7epss 0.00

    Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulnerability in the AWCC. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2026-21426MedMar 4, 2026
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service,…

  • CVE-2026-21424MedMar 4, 2026
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…

  • CVE-2026-21421MedMar 4, 2026
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of…

  • CVE-2025-37128MedSep 16, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an…

  • CVE-2025-21110MedAug 14, 2025
    risk 0.44cvss 6.7epss 0.00

    Dell Data Lakehouse, versions prior to 1.5.0.0, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2025-3892MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to…

  • CVE-2025-43487MedJul 23, 2025
    risk 0.44cvss 6.8epss 0.00

    A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not properly implement access controls. HP has addressed the issue in the latest software update.

  • CVE-2025-3364MedApr 8, 2025
    risk 0.44cvss 6.7epss 0.00

    The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system.

  • CVE-2024-27146MedJun 14, 2024
    risk 0.44cvss 6.7epss 0.00

    The Toshiba printers do not implement privileges separation. As for the affected products/models/versions, see the reference URL.

  • CVE-2024-25967MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-45592MedMar 5, 2024
    risk 0.44cvss 6.8epss 0.01

    A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root privileges) exacerbates the impacts of successful attacks executed against the browser. This…

  • CVE-2023-32486MedAug 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges.