VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 22 of 88
  • CVE-2025-3394HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

  • CVE-2024-13861HigApr 11, 2025
    risk 0.51cvss 7.8epss 0.00

    A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.

  • CVE-2025-27688HigMar 18, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-22454HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

  • CVE-2025-21325HigJan 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

  • CVE-2024-11220HigDec 6, 2024
    risk 0.51cvss 7.8epss 0.00

    A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.

  • CVE-2024-9245HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute…

  • CVE-2024-9244HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute…

  • CVE-2024-7245HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute…

  • CVE-2024-6871HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute…

  • CVE-2024-39709HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.

  • CVE-2024-47783HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and…

  • CVE-2024-50590HigNov 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions. The default installation directory of Elefant is "C:\Elefant1" which is …

  • CVE-2024-22029HigOct 16, 2024
    risk 0.51cvss 7.8epss 0.00

    Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

  • CVE-2024-6510HigSep 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.

  • CVE-2024-38456HigSep 3, 2024
    risk 0.51cvss 7.8epss 0.00

    HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerability in prunsrv.exe. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute…

  • CVE-2024-5930HigAug 21, 2024
    risk 0.51cvss 7.8epss 0.00

    VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute…

  • CVE-2024-5915HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.

  • CVE-2024-31202HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

  • CVE-2024-30369HigJun 6, 2024
    risk 0.51cvss 7.8epss 0.00

    A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of A10 Thunder ADC. An attacker must first obtain the ability to execute low-privileged code on…