VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 29 of 79
  • CVE-2020-13884HigJun 8, 2020
    risk 0.51cvss 7.8epss 0.01

    Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.

  • CVE-2020-13149HigMay 18, 2020
    risk 0.51cvss 7.8epss 0.00

    Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated users to overwrite system files and gain escalated privileges. One attack method is to change the…

  • CVE-2020-0024HigMay 14, 2020
    risk 0.51cvss 7.8epss 0.00

    In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-5896HigMay 12, 2020
    risk 0.51cvss 7.8epss 0.00

    On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder permissions.

  • CVE-2020-8471HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+…

  • CVE-2020-0547HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-4270HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.

  • CVE-2019-14326HigApr 14, 2020
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) with root privileges in the emulated Android system. This can be exploited by remote attackers to gain full access to the device, or by malicious apps…

  • CVE-2020-1985HigApr 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escalated privileges. This issue affects all versions Secdo for Windows.

  • CVE-2020-10939HigMar 27, 2020
    risk 0.51cvss 7.8epss 0.00

    Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.

  • CVE-2020-3766HigMar 25, 2020
    risk 0.51cvss 7.8epss 0.01

    Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2020-0514HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0508HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-5342HigMar 9, 2020
    risk 0.51cvss 7.8epss 0.00

    Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileged malicious user could exploit this vulnerability to run an arbitrary executable with administrative privileges on the affected system.

  • CVE-2020-3838HigFeb 27, 2020
    risk 0.51cvss 7.8epss 0.02

    The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges.

  • CVE-2020-0564HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0562HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0560HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-14002HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU,…

  • CVE-2014-7303HigJan 27, 2020
    risk 0.51cvss 7.8epss 0.01

    SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.