VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 16 of 79
  • CVE-2025-8098HigAug 18, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.

  • CVE-2025-8672HigAug 11, 2025
    risk 0.51cvss 7.8epss 0.00

    MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts,…

  • CVE-2025-52361HigAug 1, 2025
    risk 0.51cvss 7.8epss 0.00

    Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authenticated low-privilege user to execute arbitrary commands with root privilege via editing this script which is executed with root-privileges…

  • CVE-2025-8069HigJul 23, 2025
    risk 0.51cvss 7.8epss 0.00

    During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ssl directory location to fetch the OpenSSL configuration file. As a result, a non-admin user could place arbitrary code in the…

  • CVE-2025-0886HigJul 17, 2025
    risk 0.51cvss 7.8epss 0.00

    An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate privileges.

  • CVE-2025-36632HigJun 16, 2025
    risk 0.51cvss 7.8epss 0.00

    In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.

  • CVE-2025-23105HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2025-2502HigMay 30, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

  • CVE-2025-43596HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).

  • CVE-2025-43595HigMay 1, 2025
    risk 0.51cvss 7.8epss 0.00

    An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).

  • CVE-2025-42598HigApr 28, 2025
    risk 0.51cvss 7.8epss 0.00

    Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may…

  • CVE-2025-24914HigApr 18, 2025
    risk 0.51cvss 7.8epss 0.00

    When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation…

  • CVE-2025-3617HigApr 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat…

  • CVE-2025-23386HigApr 10, 2025
    risk 0.51cvss 7.8epss 0.00

    A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1.

  • CVE-2025-29801HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29570HigApr 3, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check of a binary named rc.

  • CVE-2025-29504HigApr 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.

  • CVE-2025-24277HigMar 31, 2025
    risk 0.51cvss 7.8epss 0.00

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

  • CVE-2025-24267HigMar 31, 2025
    risk 0.51cvss 7.8epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

  • CVE-2025-24234HigMar 31, 2025
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to gain root privileges.