Falhas do tipo CWE-272

35 resultados

Violação do Princípio do Menor Privilégio

Ocorre quando um processo, usuário ou componente opera com mais permissões do que o necessário para executar sua função legítima. Isso amplia a superfície de ataque: se o código for comprometido, o atacante herda todos os privilégios desnecessários, facilitando movimentação lateral, escalação de privilégio ou acesso a dados sensíveis que não deveria ter.

Exemplo

Um serviço de processamento de imagens que roda como root ou SYSTEM, quando poderia rodar com usuário restrito sem permissão de escrita em diretórios críticos. Se vulnerável, o atacante ganha controle total da máquina em vez de acesso apenas aos diretórios de trabalho.

Como mitigar

Execute processos com a menor permissão possível (use contas de serviço dedicadas e não-privilegiadas, implemente sandboxing quando viável). Na infraestrutura, aplique segregação de funções: quem precisa ler não precisa escrever, quem precisa escrita temporária não precisa persistência. Monitore e revise regularmente as permissões atribuídas.

CVE-2026-11494MEDIUMTOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violationEPSS 0.2%CVE-2026-11554MEDIUMTOTOLINK CP450 vsftpd vsftpd.conf least privilege violationEPSS 0.2%CVE-2024-0638HIGHPrivilege escalation in mk_oracle pluginsEPSS 0.2%CVE-2025-68267MEDIUMIn JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installaEPSS 0.2%CVE-2024-28824HIGHPrivilege escalation in mk_informix pluginEPSS 0.2%CVE-2024-28829MEDIUMPrivilege escalation in mk_informix pluginEPSS 0.2%CVE-2026-35535HIGHIn Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailerEPSS 0.2%CVE-2023-28047HIGH Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local loEPSS 0.2%CVE-2025-8758HIGHTRENDnet TEW-822DRE vsftpd least privilege violationEPSS 0.2%CVE-2023-32451HIGH Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during instEPSS 0.2%CVE-2025-8757HIGHTRENDnet TV-IP110WN Embedded Boa Web Server boa.conf least privilege violationEPSS 0.2%CVE-2023-28046MEDIUM Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during uninstallation A local lEPSS 0.1%CVE-2025-47809HIGHWibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitatiEPSS 0.1%CVE-2025-9711HIGHPrivilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2bEPSS 0.1%CVE-2026-32655MEDIUMDell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attackEPSS 0.1%