VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,582)

page 22 of 80
  • CVE-2024-0833HigJan 31, 2024
    risk 0.51cvss 7.8epss 0.00

    In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to…

  • CVE-2024-21840HigJan 30, 2024
    risk 0.51cvss 7.9epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.

  • CVE-2023-50612HigJan 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.

  • CVE-2023-41718HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.

  • CVE-2023-35080HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or…

  • CVE-2023-41726HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.01

    Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability

  • CVE-2023-3112HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.

  • CVE-2023-35183HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse local resources to Privilege Escalation.

  • CVE-2023-35181HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder permission resulting in Privilege Escalation.

  • CVE-2023-44157HigSep 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 35979.

  • CVE-2022-43702HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.

  • CVE-2022-43701HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.

  • CVE-2023-38410HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A user may be able to elevate privileges.

  • CVE-2023-26077HigJul 24, 2023
    risk 0.51cvss 7.8epss 0.00

    Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2023-32183HigJul 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed.

  • CVE-2023-21187HigJun 28, 2023
    risk 0.51cvss 7.8epss 0.00

    In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21175HigJun 28, 2023
    risk 0.51cvss 7.8epss 0.00

    In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-20178HigJun 28, 2023
    risk 0.51cvss 7.8epss 0.05

    A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update…

  • CVE-2023-32405HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to gain root privileges.

  • CVE-2023-32351HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges.