VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 38 of 80
  • CVE-2025-11567HigNov 12, 2025
    risk 0.47cvss —epss 0.00

    CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not properly secured.

  • CVE-2025-46355HigJun 3, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.

  • CVE-2024-13948HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

  • CVE-2023-31359HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31358HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-36339HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-21960HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2025-30701HigApr 15, 2025
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in the RAS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via Oracle…

  • CVE-2025-0014HigApr 2, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31360HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2018-9369HigNov 19, 2024
    risk 0.47cvss 7.3epss 0.00

    In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-21820HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.00

    Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-21958HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-21957HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-21946HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-21945HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-21939HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-21938HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-21937HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2022-25776HigSep 18, 2024
    risk 0.47cvss 8.3epss 0.00

    Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.