VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 50 of 88
  • CVE-2023-41776MedJan 3, 2024
    risk 0.44cvss 6.7epss 0.00

    There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

  • CVE-2023-39230MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-34997MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-34314MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41700MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-33898MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28658MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-38497HigAug 4, 2023
    risk 0.44cvss 7.9epss 0.01

    Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files…

  • CVE-2022-46656MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41658MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-38103MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access

  • CVE-2022-37771MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.

  • CVE-2022-36670MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.

  • CVE-2021-44167MedMay 11, 2022
    risk 0.44cvss 6.8epss 0.01

    An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories…

  • CVE-2021-35248MedDec 20, 2021
    risk 0.44cvss 6.8epss 0.01

    It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.

  • CVE-2021-0904MedDec 15, 2021
    risk 0.44cvss 6.7epss 0.00

    In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; Issue ID: ALPS06076938.

  • CVE-2021-40067MedSep 16, 2021
    risk 0.44cvss 6.8epss 0.01

    The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of…

  • CVE-2021-21177MedMar 9, 2021
    risk 0.44cvss 6.5epss 0.17

    Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2020-5385MedAug 18, 2020
    risk 0.44cvss 6.7epss 0.00

    Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to…

  • CVE-2020-5358MedJun 15, 2020
    risk 0.44cvss 6.7epss 0.00

    Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated…