VYPR

CWE-250

Execution with Unnecessary Privileges

BaseDraftLikelihood: Medium

Description

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-470 · CAPEC-69

CVEs mapped to this weakness (358)

page 6 of 18
  • CVE-2025-33108HigJun 14, 2025
    risk 0.55cvss 8.5epss 0.01

    IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause user-controlled code to run with…

  • CVE-2025-33103HigMay 17, 2025
    risk 0.55cvss 8.5epss 0.00

    IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.

  • CVE-2025-1951HigApr 22, 2025
    risk 0.55cvss 8.4epss 0.00

    IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.

  • CVE-2024-35142HigMay 31, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force ID: 292418.

  • CVE-2024-27260HigMay 16, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.

  • CVE-2024-27110HigMay 14, 2024
    risk 0.55cvss 8.4epss 0.00

    Elevation of privilege vulnerability in GE HealthCare EchoPAC products

  • CVE-2022-41290HigDec 23, 2022
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.

  • CVE-2025-67510CriDec 10, 2025
    risk 0.54cvss 9.4epss 0.00

    Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”),…

  • CVE-2023-27313HigOct 12, 2023
    risk 0.54cvss 8.3epss 0.01

    SnapCenter versions 3.x and 4.x prior to 4.9 are susceptible to a vulnerability which may allow an authenticated unprivileged user to gain access as an admin user.

  • CVE-2023-27010HigMar 13, 2023
    risk 0.54cvss 7.8epss 0.01

    Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability allows attackers to escalate privileges via modifying or overwriting the executable.

  • CVE-2026-17445HigAug 12, 2026
    risk 0.53cvss 8.2epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name.

  • CVE-2024-21924HigFeb 11, 2025
    risk 0.53cvss 8.2epss 0.00

    SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentially resulting in arbitrary code execution.

  • CVE-2024-20999HigApr 16, 2024
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Zones). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle…

  • CVE-2023-5207HigSep 30, 2023
    risk 0.53cvss 8.2epss 0.01

    A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

  • CVE-2022-22239HigOct 18, 2022
    risk 0.53cvss 8.2epss 0.00

    An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges to escalate their privileges on the device and potentially remote systems. This vulnerability allows…

  • CVE-2021-1579HigAug 25, 2021
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to elevate privileges…

  • CVE-2025-23181HigApr 29, 2025
    risk 0.52cvss 8.0epss 0.00

    CWE-250: Execution with Unnecessary Privileges

  • CVE-2025-23180HigApr 29, 2025
    risk 0.52cvss 8.0epss 0.00

    CWE-250: Execution with Unnecessary Privileges

  • CVE-2024-7387CriSep 17, 2024
    risk 0.52cvss 9.1epss 0.02

    A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the…

  • CVE-2023-1943HigOct 12, 2023
    risk 0.52cvss 8.0epss 0.01

    Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.