CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,561)
page 21 of 79| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-1155 | Hig | 0.51 | 7.8 | 0.00 | Feb 20, 2024 | Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2024-0034 | Hig | 0.51 | 7.8 | 0.00 | Feb 16, 2024 | In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-50236 | Hig | 0.51 | 7.8 | 0.00 | Feb 13, 2024 | A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissions in the installation path. An attacker with local access could exploit this vulnerability to escalate privileges to NT… | ||
| CVE-2024-0833 | Hig | 0.51 | 7.8 | 0.00 | Jan 31, 2024 | In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to… | ||
| CVE-2024-21840 | Hig | 0.51 | 7.9 | 0.00 | Jan 30, 2024 | Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2. | ||
| CVE-2023-50612 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2024 | Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter. | ||
| CVE-2023-41718 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2023 | When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file. | ||
| CVE-2023-35080 | Hig | 0.51 | 7.8 | 0.01 | Nov 15, 2023 | A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or… | ||
| CVE-2023-41726 | Hig | 0.51 | 7.8 | 0.01 | Nov 3, 2023 | Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability | ||
| CVE-2023-3112 | Hig | 0.51 | 7.8 | 0.00 | Oct 25, 2023 | A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges. | ||
| CVE-2023-35183 | Hig | 0.51 | 7.8 | 0.00 | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse local resources to Privilege Escalation. | ||
| CVE-2023-35181 | Hig | 0.51 | 7.8 | 0.00 | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder permission resulting in Privilege Escalation. | ||
| CVE-2023-44157 | Hig | 0.51 | 7.8 | 0.00 | Sep 27, 2023 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 35979. | ||
| CVE-2022-43702 | Hig | 0.51 | 7.8 | 0.00 | Jul 27, 2023 | When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code. | ||
| CVE-2022-43701 | Hig | 0.51 | 7.8 | 0.00 | Jul 27, 2023 | When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code. | ||
| CVE-2023-38410 | Hig | 0.51 | 7.8 | 0.00 | Jul 27, 2023 | The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A user may be able to elevate privileges. | ||
| CVE-2023-26077 | Hig | 0.51 | 7.8 | 0.00 | Jul 24, 2023 | Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions. | ||
| CVE-2023-32183 | Hig | 0.51 | 7.8 | 0.00 | Jul 7, 2023 | Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed. | ||
| CVE-2023-21187 | Hig | 0.51 | 7.8 | 0.00 | Jun 28, 2023 | In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21175 | Hig | 0.51 | 7.8 | 0.00 | Jun 28, 2023 | In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… |
- risk 0.51cvss 7.8epss 0.00
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissions in the installation path. An attacker with local access could exploit this vulnerability to escalate privileges to NT…
- risk 0.51cvss 7.8epss 0.00
In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to…
- risk 0.51cvss 7.9epss 0.00
Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.
- risk 0.51cvss 7.8epss 0.00
Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.
- risk 0.51cvss 7.8epss 0.00
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
- risk 0.51cvss 7.8epss 0.01
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or…
- risk 0.51cvss 7.8epss 0.01
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.
- risk 0.51cvss 7.8epss 0.00
The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse local resources to Privilege Escalation.
- risk 0.51cvss 7.8epss 0.00
The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder permission resulting in Privilege Escalation.
- risk 0.51cvss 7.8epss 0.00
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 35979.
- risk 0.51cvss 7.8epss 0.00
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.
- risk 0.51cvss 7.8epss 0.00
When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.
- risk 0.51cvss 7.8epss 0.00
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A user may be able to elevate privileges.
- risk 0.51cvss 7.8epss 0.00
Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.
- risk 0.51cvss 7.8epss 0.00
Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed.
- risk 0.51cvss 7.8epss 0.00
In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…