VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 28 of 80
  • CVE-2020-0486HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege to change contact data with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-5798HigDec 7, 2020
    risk 0.51cvss 7.8epss 0.00

    inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.

  • CVE-2020-13542HigDec 3, 2020
    risk 0.51cvss 7.8epss 0.01

    A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an attacker can either replace the service binary or replace DLL files loaded by the service, both which get executed by a service…

  • CVE-2020-24456HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the Intel(R) Board ID Tool version v.1.01 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-12346HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-13770HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service…

  • CVE-2020-12354HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-12307HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in some Intel(R) High Definition Audio drivers before version 9.21.00.4561 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-12306HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the Intel(R) RealSense(TM) D400 Series Dynamic Calibration Tool before version 2.11, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-13537HigNov 5, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService, which starts as a NT…

  • CVE-2020-13536HigNov 5, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewService, which starts as a NT…

  • CVE-2020-15850HigSep 24, 2020
    risk 0.51cvss 7.8epss 0.01

    Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the…

  • CVE-2020-0374HigSep 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156251602

  • CVE-2020-0275HigSep 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass. This could lead to local escalation of privilege, with no additional execution privileges needed. User interaction is not…

  • CVE-2020-0388HigSep 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2020-10050HigSep 9, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service executables of the affected application could allow a local attacker to include arbitrary commands that are executed with SYSTEM privileges when the system…

  • CVE-2019-10679HigSep 3, 2020
    risk 0.51cvss 7.8epss 0.00

    Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eikon permissions.

  • CVE-2020-7527HigAug 31, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.

  • CVE-2020-8763HigAug 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-8743HigAug 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.