VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 37 of 79
  • CVE-2020-1571HigAug 17, 2020
    risk 0.48cvss 7.3epss 0.01

    An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions. A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker could then install programs;…

  • CVE-2020-9392HigMar 23, 2020
    risk 0.48cvss 7.3epss 0.02

    An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new…

  • CVE-2018-6683HigJul 23, 2018
    risk 0.48cvss 7.4epss 0.00

    Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline.

  • CVE-2026-59119HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-21074HigAug 10, 2026
    risk 0.47cvss epss 0.00

    Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.

  • CVE-2025-7024HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.00

    Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the vulnerable…

  • CVE-2025-8485HigNov 12, 2025
    risk 0.47cvss 7.3epss 0.00

    An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.

  • CVE-2025-11567HigNov 12, 2025
    risk 0.47cvss epss 0.00

    CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not properly secured.

  • CVE-2025-46355HigJun 3, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.

  • CVE-2024-13948HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

  • CVE-2023-31359HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31358HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-36339HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-21960HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2025-30701HigApr 15, 2025
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in the RAS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via Oracle…

  • CVE-2025-0014HigApr 2, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31360HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2018-9369HigNov 19, 2024
    risk 0.47cvss 7.3epss 0.00

    In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-21820HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.00

    Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-21958HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.