VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 45 of 79
  • CVE-2023-29244MedJan 19, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop Element software installers before version 5.4.1.4479 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32638MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27305MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-4575MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

  • CVE-2022-3431MedOct 9, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2023-32663MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32547MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the MAVinci Desktop Software for Intel(R) Falcon 8+ before version 6.2 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32543MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-31246MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27505MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installers before version 22.1 .1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-45853MedMay 30, 2023
    risk 0.44cvss 6.7epss 0.00

    The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some system commands as 'root' on a vulnerable…

  • CVE-2023-27382MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-22440MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41687MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-40971MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-36391MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-33963MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-30338MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-3432MedJan 26, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2022-3430MedJan 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.