VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 43 of 79
  • CVE-2025-12100HigOct 23, 2025
    risk 0.44cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6.

  • CVE-2025-27559MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-26470MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-20087MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-20023MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-48959MedJun 4, 2025
    risk 0.44cvss 6.7epss 0.00

    Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40077.

  • CVE-2025-20984MedJun 4, 2025
    risk 0.44cvss 6.8epss 0.00

    Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch.

  • CVE-2025-20095MedMay 13, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-47550MedMay 13, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-28954MedMay 13, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-27521MedMar 4, 2025
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-42419MedFeb 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-32942MedFeb 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-24826MedJan 28, 2025
    risk 0.44cvss 6.7epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.

  • CVE-2024-55930MedJan 23, 2025
    risk 0.44cvss 6.7epss 0.00

    Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files

  • CVE-2024-50657MedNov 22, 2024
    risk 0.44cvss 6.8epss 0.00

    An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method

  • CVE-2017-13311MedNov 15, 2024
    risk 0.44cvss 6.7epss 0.00

    In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges…

  • CVE-2024-35201MedNov 13, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access.

  • CVE-2024-29083MedNov 13, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-25647MedNov 13, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated user to potentially enable escalation of privilege via local access.