VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 27 of 88
  • CVE-2021-0570HigJun 22, 2021
    risk 0.51cvss 7.8epss 0.00

    In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-27483HigJun 16, 2021
    risk 0.51cvss 7.8epss 0.00

    ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.

  • CVE-2021-0477HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2021-23022HigJun 10, 2021
    risk 0.51cvss 7.8epss 0.00

    On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2021-0102HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0077HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0056HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0055HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before version 10.42 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-32460HigJun 3, 2021
    risk 0.51cvss 7.8epss 0.00

    The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. Please note than an attacker must already have local user…

  • CVE-2021-31155HigMay 27, 2021
    risk 0.51cvss 7.8epss 0.00

    Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are allowed to execute at least one command.

  • CVE-2021-22117HigMay 18, 2021
    risk 0.51cvss 7.8epss 0.01

    RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.

  • CVE-2021-31167HigMay 11, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Container Manager Service Elevation of Privilege Vulnerability

  • CVE-2021-28098HigApr 14, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMDATA%\ForeScout SecureConnector\ that has…

  • CVE-2021-22716HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior)

  • CVE-2021-28645HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2021-25253HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.02

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain…

  • CVE-2021-25250HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…

  • CVE-2020-26155HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.00

    Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable…

  • CVE-2021-0372HigMar 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0109HigFeb 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authenticated user to potentially enable escalation of privilege via local access.