VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 26 of 80
  • CVE-2021-43325HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.

  • CVE-2021-42711HigDec 1, 2021
    risk 0.51cvss 7.8epss 0.00

    Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair operation.

  • CVE-2021-31822HigNov 24, 2021
    risk 0.51cvss 7.8epss 0.00

    When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local unprivileged user modifying the contents of the systemd service file to gain privileged access.

  • CVE-2021-33071HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33062HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0065HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-8741HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33092HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit HID Event Filter driver pack before version 2.2.1.383 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33090HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissionsin the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC10i3FN, NUC10i5FN, NUC10i7FN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33088HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack before version 5.4.1.4449 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-38420HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

  • CVE-2021-3579HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate privileges to NT AUTHORITY\SYSTEM This issue affects:…

  • CVE-2021-37363HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.02

    An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt…

  • CVE-2021-42011HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2021-20037HigSep 21, 2021
    risk 0.51cvss 7.8epss 0.00

    SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host operating system. This vulnerability impacts GVC 4.10.5 installer and earlier.

  • CVE-2021-36795HigAug 6, 2021
    risk 0.51cvss 7.8epss 0.00

    A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.0a to 6.6.0b-hotfix1. An underprivileged linux user, if certain environment criteria are met, can gain additional privileges.

  • CVE-2021-32464HigAug 4, 2021
    risk 0.51cvss 7.8epss 0.01

    An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain…

  • CVE-2021-0486HigJul 14, 2021
    risk 0.51cvss 7.8epss 0.00

    In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0143HigJun 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0106HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the Intel(R) Optane(TM) DC Persistent Memory for Windows software versions before 2.00.00.3842 or 1.00.00.3515 may allow an authenticated user to potentially enable escalation of privilege via local access.