VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 16 of 80
  • CVE-2025-58097HigNov 21, 2025
    risk 0.51cvss 7.8epss 0.00

    The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege.

  • CVE-2025-34333HigNov 19, 2025
    risk 0.51cvss 7.8epss 0.00

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated…

  • CVE-2025-34332HigNov 19, 2025
    risk 0.51cvss 7.8epss 0.00

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain…

  • CVE-2025-13131HigNov 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results in incorrect default permissions. The attack is only possible with…

  • CVE-2025-13130HigNov 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Console.exe of the component Service. Such manipulation leads to incorrect default permissions. The attack can only be performed from a…

  • CVE-2025-23347HigOct 23, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

  • CVE-2025-11575HigOct 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0.

  • CVE-2025-23297HigOct 1, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in the Frameview SDK directory. A successful exploit of this vulnerability might lead to escalation of…

  • CVE-2025-43725HigSep 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2025-57846HigAug 27, 2025
    risk 0.51cvss 7.8epss 0.00

    Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a local authenticated attacker may replace a service executable on the system where the product is running, potentially allowing arbitrary code execution…

  • CVE-2025-8098HigAug 18, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.

  • CVE-2025-8672HigAug 11, 2025
    risk 0.51cvss 7.8epss 0.00

    MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts,…

  • CVE-2025-52361HigAug 1, 2025
    risk 0.51cvss 7.8epss 0.00

    Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authenticated low-privilege user to execute arbitrary commands with root privilege via editing this script which is executed with root-privileges…

  • CVE-2025-8069HigJul 23, 2025
    risk 0.51cvss 7.8epss 0.00

    During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ssl directory location to fetch the OpenSSL configuration file. As a result, a non-admin user could place arbitrary code in the…

  • CVE-2025-0886HigJul 17, 2025
    risk 0.51cvss 7.8epss 0.00

    An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate privileges.

  • CVE-2025-36632HigJun 16, 2025
    risk 0.51cvss 7.8epss 0.00

    In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.

  • CVE-2025-23105HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2025-2502HigMay 30, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

  • CVE-2025-43596HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).

  • CVE-2025-43595HigMay 1, 2025
    risk 0.51cvss 7.8epss 0.00

    An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).