VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 30 of 79
  • CVE-2014-7302HigJan 27, 2020
    risk 0.51cvss 7.8epss 0.01

    SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.

  • CVE-2019-14601HigJan 17, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-11097HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially…

  • CVE-2019-19675HigDec 17, 2019
    risk 0.51cvss 7.8epss 0.00

    In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, the attacker can start applications that…

  • CVE-2019-14605HigDec 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack.

  • CVE-2019-14603HigDec 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-14568HigDec 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-0134HigDec 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an authenticated user to potentially execute code at an elevated level of privilege.

  • CVE-2019-17421HigNov 21, 2019
    risk 0.51cvss 7.8epss 0.01

    Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.

  • CVE-2019-14602HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-17044HigOct 14, 2019
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" privileges to elevate his/her privileges to the ones of the "root" user by specially crafting a shared library .so file that will…

  • CVE-2019-17043HigOct 14, 2019
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during…

  • CVE-2019-2173HigOct 11, 2019
    risk 0.51cvss 7.8epss 0.00

    In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2019-2114HigOct 11, 2019
    risk 0.51cvss 7.8epss 0.00

    In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission. This could lead to local escalation of privilege by installing an application with no additional execution privileges needed.…

  • CVE-2019-17365HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.00

    Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.

  • CVE-2019-16913HigOct 7, 2019
    risk 0.51cvss 7.8epss 0.00

    PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permission "Everyone: (F)" to the contents of the directory and its subfolders. In addition, the program installs a service called…

  • CVE-2018-19592HigSep 27, 2019
    risk 0.51cvss 7.8epss 0.01

    The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue…

  • CVE-2018-11906HigNov 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a security concern with default privileged access to ADB and debug-fs.

  • CVE-2018-12441HigOct 11, 2018
    risk 0.51cvss 7.8epss 0.01

    The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system.…

  • CVE-2018-12175HigSep 12, 2018
    risk 0.51cvss 7.8epss 0.00

    Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access.