VYPR

CWE-279

Incorrect Execution-Assigned Permissions

VariantDraft

Description

While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-81

CVEs mapped to this weakness (28)

page 2 of 2
  • CVE-2025-20612MedMay 13, 2025
    risk 0.36cvss 5.5epss 0.00

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2017-8441MedJun 5, 2017
    risk 0.28cvss 4.3epss 0.01

    Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an…

  • CVE-2025-26422MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-36228LowDec 26, 2025
    risk 0.25cvss 3.8epss 0.00

    IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.

  • CVE-2025-23233LowMay 13, 2025
    risk 0.23cvss 3.5epss 0.00

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2024-39286LowFeb 12, 2025
    risk 0.21cvss 3.3epss 0.00

    Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2026-46388MedJul 10, 2026
    risk 0.00cvss 4.4epss 0.00

    osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve…

  • CVE-2024-37734CriJun 26, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.