VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 45 of 80
  • CVE-2024-22378MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-43747MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-38459HigJun 16, 2024
    risk 0.44cvss 7.8epss 0.00

    langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.

  • CVE-2024-27180MedJun 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.

  • CVE-2023-42668MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based on Intel(R) 62X Chipset may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-42433MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-34011MedApr 29, 2024
    risk 0.44cvss 6.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758.

  • CVE-2024-2859MedApr 27, 2024
    risk 0.44cvss 6.8epss 0.01

    By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.

  • CVE-2024-25958MedMar 26, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege escalation, unauthorized access to application data,…

  • CVE-2023-28389MedMar 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-49721MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

  • CVE-2023-41231MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-40154MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable escalation of privilege via local access.

  • CVE-2023-34315MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28739MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-29244MedJan 19, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop Element software installers before version 5.4.1.4479 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32638MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27305MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-4575MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

  • CVE-2022-3431MedOct 9, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.