Fallos del tipo CWE-274

42 resultados

Escalação de privilégio

É quando um atacante consegue obter permissões ou acesso mais altos do que deveria ter na aplicação ou sistema. O código falha em validar adequadamente quem pode realizar certas ações, permitindo que um usuário comum acesse funcionalidades administrativas ou dados de outros usuários.

Ejemplo

Um usuário logado como 'cliente' manipula um parâmetro de URL (ex: user_id=1) para acessar dados ou funções reservadas ao administrador, porque a aplicação nunca verificou se esse usuário realmente tem permissão para tal operação.

Cómo mitigar

Implemente controle de acesso em todos os pontos sensíveis: valide a identidade e permissões do usuário antes de cada ação administrativo ou de dados. Use padrões como RBAC (controle por papéis) ou ABAC (controle por atributos), e revise regularmente quem tem acesso a quê.

CVE-2024-0105HIGHNVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A succeEPSS 0.3%CVE-2020-7265HIGHPrivilege Escalation vulnerability through symbolic links in ENSMEPSS 0.3%CVE-2020-7267HIGHPrivilege Escalation vulnerability through symbolic links in VSELEPSS 0.3%CVE-2020-7264HIGHPrivilege Escalation vulnerability through symbolic links in ENS for WindowsEPSS 0.3%CVE-2020-7266HIGHPrivilege Escalation vulnerability through symbolic links in VSE for WindowsEPSS 0.3%CVE-2020-7286HIGHPrivilege Escalation vulnerability in EDR for WindowsEPSS 0.3%CVE-2020-7285HIGHPrivilege Escalation vulnerability in MVISION EndpointEPSS 0.3%CVE-2020-7290HIGHPrivilege Escalation vulnerability in MAR for LinuxEPSS 0.3%CVE-2020-7287HIGHPrivilege Escalation vulnerability in EDR for LinuxEPSS 0.3%CVE-2020-7288HIGHPrivilege Escalation vulnerability in EDR for MacEPSS 0.3%CVE-2020-7291HIGHPrivilege Escalation vulnerability MAR for MacEPSS 0.3%CVE-2025-62175MEDIUMMastodon streaming API fails to disconnect disabled and suspended usersEPSS 0.2%CVE-2025-54511MEDIUMImproper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a functiEPSS 0.2%CVE-2025-31275MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able tEPSS 0.2%CVE-2018-6693MEDIUMEndpoint Security for Linux Threat Prevention (ENSLTP) privilege escalation vulnerabilityEPSS 0.2%CVE-2023-20516LOWImproper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentEPSS 0.2%CVE-2018-6674MEDIUMPrivilege escalation vulnerability in McAfee VSE when McTray run with elevated privilegesEPSS 0.2%CVE-2024-0106HIGHNVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper EPSS 0.2%CVE-2023-32494MEDIUM Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker coEPSS 0.2%CVE-2024-46974HIGHGPU DDK - Arbitrary write of read-only dmabufEPSS 0.2%