Falhas do tipo CWE-274

42 resultados

Elevação de Privilégio

É quando um atacante consegue obter permissões ou direitos superiores aos que deveria ter — passando de usuário comum para administrador, ou de aplicação limitada para acesso ao kernel, por exemplo. O risco é grave porque permite ao invasor contornar controles de segurança e acessar dados ou funcionalidades restritas.

Exemplo

Um serviço web roda com privilégios de root e aceita comandos do usuário sem validação adequada. Um atacante injeta um comando que cria uma nova conta administrativa, obtendo controle total do servidor.

Como mitigar

Execute processos com o menor privilégio possível (princípio do menor privilégio), valide rigorosamente todas as entradas do usuário, implemente controle de acesso baseado em papéis (RBAC) e mantenha auditoria de operações sensíveis. Use containerização ou sandboxing para isolar serviços críticos.

CVE-2021-35534HIGHInsufficient Security Control VulnerabilityEPSS 1.7%CVE-2025-20156CRITICALCisco Meeting Management Client-Server Privilege Escalation VulnerabilityEPSS 1.2%CVE-2023-35928HIGHNextcloud user scoped external storage can be used to gather credentials of other usersEPSS 1.0%CVE-2022-45101HIGH Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthentiEPSS 0.8%CVE-2021-32006MEDIUMGateManager information leak for LinkManager UsersEPSS 0.6%CVE-2022-0668MEDIUMJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted rEPSS 0.6%CVE-2023-39375HIGHSiberianCMS - CWE-274: Improper Handling of Insufficient PrivilegesEPSS 0.6%CVE-2020-7283HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.6%CVE-2024-41942HIGHJupyterHub has a privilege escalation vulnerability with the `admin:users` scopeEPSS 0.6%CVE-2024-21648HIGHXWiki has no right protection on rollback actionEPSS 0.5%CVE-2025-29365CRITICALspimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.EPSS 0.5%CVE-2024-12666MEDIUMClassCMS User Management Page admin insufficient privilegesEPSS 0.5%CVE-2022-23160MEDIUMDell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An remote malicious usEPSS 0.5%CVE-2022-23511HIGHA privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2EPSS 0.5%CVE-2022-25782MEDIUMInsufficient privilege checks on object access and updates.EPSS 0.5%CVE-2026-33005MEDIUMApache OpenMeetings: Insufficient checks in FileWebServiceEPSS 0.4%CVE-2017-3912MEDIUMMcAfee Application Control and Change Control (MACC) - password management security feature bypass (SFB) leading to an authentication bypassEPSS 0.4%CVE-2020-24676HIGHInsecure Windows Services in Symphony PlusEPSS 0.4%CVE-2020-7289HIGHPrivilege Escalation vulnerability in MAR for WindowsEPSS 0.3%CVE-2026-62764MEDIUMApache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissionsEPSS 0.3%