VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 22 of 79
  • CVE-2023-20178HigJun 28, 2023
    risk 0.51cvss 7.8epss 0.05

    A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update…

  • CVE-2023-32405HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to gain root privileges.

  • CVE-2023-32351HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges.

  • CVE-2023-30905HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.00

    The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege.

  • CVE-2023-21139HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21138HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed…

  • CVE-2023-21129HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background due to a BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-21128HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21126HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21121HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2022-4569HigJun 5, 2023
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.

  • CVE-2023-29733HigMay 30, 2023
    risk 0.51cvss 7.8epss 0.00

    The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation,…

  • CVE-2023-29838HigMay 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Insecure Permission vulnerability found in Botkind/Siber Systems SyncApp v.19.0.3.0 allows a local attacker toe escalate privileges via the SyncService.exe file.

  • CVE-2023-33240HigMay 19, 2023
    risk 0.51cvss 7.8epss 0.00

    Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory…

  • CVE-2022-45452HigMay 18, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2023-21107HigMay 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local escalation of privilege across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-38583HigApr 28, 2023
    risk 0.51cvss 7.8epss 0.00

    On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstation user could abuse their access to the "SharedData" folder on the connected Sage 300 server to…

  • CVE-2022-31244HigApr 25, 2023
    risk 0.51cvss 7.8epss 0.00

    Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

  • CVE-2021-41614HigApr 18, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to the Exception Program Counter Register (EPCR) are not implemented correctly. User programs from an unauthorized privilege level can make read/write accesses to…

  • CVE-2023-28966HigApr 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modify existing files or execute commands as root. The issue is caused by improper file and directory permissions on certain system…