VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 30 of 80
  • CVE-2020-3766HigMar 25, 2020
    risk 0.51cvss 7.8epss 0.01

    Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2020-0514HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0508HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-5342HigMar 9, 2020
    risk 0.51cvss 7.8epss 0.00

    Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileged malicious user could exploit this vulnerability to run an arbitrary executable with administrative privileges on the affected system.

  • CVE-2020-3838HigFeb 27, 2020
    risk 0.51cvss 7.8epss 0.02

    The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges.

  • CVE-2020-0564HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0562HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0560HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-14002HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU,…

  • CVE-2014-7303HigJan 27, 2020
    risk 0.51cvss 7.8epss 0.01

    SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.

  • CVE-2014-7302HigJan 27, 2020
    risk 0.51cvss 7.8epss 0.01

    SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.

  • CVE-2019-14601HigJan 17, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-11097HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially…

  • CVE-2019-19675HigDec 17, 2019
    risk 0.51cvss 7.8epss 0.00

    In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, the attacker can start applications that…

  • CVE-2019-14605HigDec 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack.

  • CVE-2019-14603HigDec 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-14568HigDec 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-0134HigDec 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an authenticated user to potentially execute code at an elevated level of privilege.

  • CVE-2019-17421HigNov 21, 2019
    risk 0.51cvss 7.8epss 0.01

    Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.

  • CVE-2019-14602HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.