VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 13 of 79
  • CVE-2016-6914HigDec 27, 2017
    risk 0.54cvss 7.8epss 0.01

    Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.

  • CVE-2016-5425HigOct 13, 2016
    risk 0.54cvss 7.8epss 0.04

    The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

  • CVE-2016-3943HigApr 18, 2016
    risk 0.54cvss 7.8epss 0.01

    Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by modifying an executable module.

  • CVE-2015-7378HigApr 18, 2016
    risk 0.54cvss 7.8epss 0.01

    Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.

  • CVE-2026-24063HigMar 18, 2026
    risk 0.53cvss 8.2epss 0.00

    When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia…

  • CVE-2025-32091HigNov 11, 2025
    risk 0.53cvss 8.2epss 0.00

    Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege.…

  • CVE-2024-46916HigAug 29, 2025
    risk 0.53cvss 8.1epss 0.00

    Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow…

  • CVE-2024-45067HigMay 14, 2025
    risk 0.53cvss 8.2epss 0.00

    Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-3528HigMay 9, 2025
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to…

  • CVE-2024-9947HigOct 23, 2024
    risk 0.53cvss 8.1epss 0.01

    The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to…

  • CVE-2024-7525HigAug 6, 2024
    risk 0.53cvss 8.1epss 0.01

    It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and…

  • CVE-2023-24460HigMay 16, 2024
    risk 0.53cvss 8.2epss 0.00

    Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-20005HigMar 4, 2024
    risk 0.53cvss 8.2epss 0.00

    In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355599; Issue ID: ALPS08355599.

  • CVE-2023-40363HigNov 18, 2023
    risk 0.53cvss 8.1epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM X-Force ID: 263332.

  • CVE-2022-45924HigJan 18, 2023
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user to delete arbitrary files on the server's local filesystem.

  • CVE-2019-9579HigDec 26, 2022
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS…

  • CVE-2022-4020HigNov 28, 2022
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.

  • CVE-2021-44905HigMar 25, 2022
    risk 0.53cvss 8.2epss 0.01

    Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via an unauthenticated edit to the lock name.

  • CVE-2022-25364HigMar 17, 2022
    risk 0.53cvss 8.1epss 0.01

    In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute…

  • CVE-2020-5906HigJul 1, 2020
    risk 0.53cvss 8.1epss 0.01

    In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted…