VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 19 of 80
  • CVE-2024-56447HigJan 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-53841HigJan 3, 2025
    risk 0.51cvss 7.8epss 0.00

    In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-53840HigJan 3, 2025
    risk 0.51cvss 7.8epss 0.00

    there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-53835HigJan 3, 2025
    risk 0.51cvss 7.8epss 0.00

    there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-11624HigJan 3, 2025
    risk 0.51cvss 7.8epss 0.00

    there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43769HigJan 3, 2025
    risk 0.51cvss 7.8epss 0.00

    In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2024-12903HigDec 23, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified…

  • CVE-2024-4229HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information…

  • CVE-2024-44224HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app may be able to gain root privileges.

  • CVE-2024-11872HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code…

  • CVE-2024-9845HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-8496HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-11598HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-11597HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-10251HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2018-9431HigDec 2, 2024
    risk 0.51cvss 7.8epss 0.00

    In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9432HigNov 19, 2024
    risk 0.51cvss 7.8epss 0.00

    In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing the user's ability to disable access to contacts, with no additional…

  • CVE-2023-21270HigNov 19, 2024
    risk 0.51cvss 7.8epss 0.00

    In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution…

  • CVE-2017-13314HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supposed to be restricted to the…

  • CVE-2017-13312HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User…