VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 24 of 88
  • CVE-2023-31871HigMay 18, 2023
    risk 0.51cvss 7.8epss 0.00

    OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing…

  • CVE-2023-1516HigMar 28, 2023
    risk 0.51cvss 7.9epss 0.00

    RoboDK versions 5.5.3 and prior contain an insecure permission assignment to critical directories vulnerability, which could allow a local user to escalate privileges and write files to the RoboDK process and achieve code execution.  

  • CVE-2023-1135HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.

  • CVE-2022-42972HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server…

  • CVE-2022-44263HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.

  • CVE-2022-43517HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service…

  • CVE-2022-44725HigNov 17, 2022
    risk 0.51cvss 7.8epss 0.00

    OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).

  • CVE-2022-44733HigNov 7, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.

  • CVE-2022-44732HigNov 7, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.

  • CVE-2022-36122HigOct 21, 2022
    risk 0.51cvss 7.8epss 0.00

    The Automox Agent before 40 on Windows incorrectly sets permissions on key files.

  • CVE-2022-20398HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2022-34891HigJul 18, 2022
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The…

  • CVE-2021-45492HigJul 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. However, this directory is writable by unprivileged users because the Sage installer fails to set…

  • CVE-2022-20218HigJul 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2022-31464HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.

  • CVE-2022-31465HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer VX.2.11 (All versions < VX.2.11 Update 11), Xpedition Designer VX.2.12 (All versions < VX.2.12 Update 5), Xpedition Designer VX.2.13 (All versions < VX.2.13…

  • CVE-2022-30700HigMay 27, 2022
    risk 0.51cvss 7.8epss 0.00

    An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2022-23743HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory allow a local attacker the ability to execute an arbitrary…

  • CVE-2022-29263HigMay 5, 2022
    risk 0.51cvss 7.8epss 0.00

    On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, the BIG-IP Edge…

  • CVE-2022-23448HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). Affected applications improperly assign permissions to critical directories and files used by the application processes.…