VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 46 of 80
  • CVE-2023-32663MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32547MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the MAVinci Desktop Software for Intel(R) Falcon 8+ before version 6.2 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32543MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-31246MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27505MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installers before version 22.1 .1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-45853MedMay 30, 2023
    risk 0.44cvss 6.7epss 0.00

    The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some system commands as 'root' on a vulnerable…

  • CVE-2023-27382MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-22440MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41687MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-40971MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-36391MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-33963MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-30338MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-3432MedJan 26, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2022-3430MedJan 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2023-20043MedJan 20, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit…

  • CVE-2022-36377MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-42464MedOct 14, 2022
    risk 0.44cvss 6.7epss 0.00

    OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could disclose sensitive…

  • CVE-2022-41748MedOct 10, 2022
    risk 0.44cvss 6.7epss 0.00

    A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative credentials to bypass certain elements of the product's anti-tampering mechanisms on affected installations. Please note: an…

  • CVE-2021-42055MedOct 18, 2021
    risk 0.44cvss 6.8epss 0.00

    ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.