Falhas do tipo CWE-274

42 resultados

Elevação de Privilégio

É quando um atacante consegue obter permissões ou direitos superiores aos que deveria ter — passando de usuário comum para administrador, ou de aplicação limitada para acesso ao kernel, por exemplo. O risco é grave porque permite ao invasor contornar controles de segurança e acessar dados ou funcionalidades restritas.

Exemplo

Um serviço web roda com privilégios de root e aceita comandos do usuário sem validação adequada. Um atacante injeta um comando que cria uma nova conta administrativa, obtendo controle total do servidor.

Como mitigar

Execute processos com o menor privilégio possível (princípio do menor privilégio), valide rigorosamente todas as entradas do usuário, implemente controle de acesso baseado em papéis (RBAC) e mantenha auditoria de operações sensíveis. Use containerização ou sandboxing para isolar serviços críticos.

CVE-2024-0105HIGHNVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A succeEPSS 0.3%CVE-2020-7265HIGHPrivilege Escalation vulnerability through symbolic links in ENSMEPSS 0.3%CVE-2020-7267HIGHPrivilege Escalation vulnerability through symbolic links in VSELEPSS 0.3%CVE-2020-7264HIGHPrivilege Escalation vulnerability through symbolic links in ENS for WindowsEPSS 0.3%CVE-2020-7266HIGHPrivilege Escalation vulnerability through symbolic links in VSE for WindowsEPSS 0.3%CVE-2020-7286HIGHPrivilege Escalation vulnerability in EDR for WindowsEPSS 0.3%CVE-2020-7285HIGHPrivilege Escalation vulnerability in MVISION EndpointEPSS 0.3%CVE-2020-7290HIGHPrivilege Escalation vulnerability in MAR for LinuxEPSS 0.3%CVE-2020-7287HIGHPrivilege Escalation vulnerability in EDR for LinuxEPSS 0.3%CVE-2020-7288HIGHPrivilege Escalation vulnerability in EDR for MacEPSS 0.3%CVE-2020-7291HIGHPrivilege Escalation vulnerability MAR for MacEPSS 0.3%CVE-2025-62175MEDIUMMastodon streaming API fails to disconnect disabled and suspended usersEPSS 0.2%CVE-2025-54511MEDIUMImproper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a functiEPSS 0.2%CVE-2025-31275MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able tEPSS 0.2%CVE-2018-6693MEDIUMEndpoint Security for Linux Threat Prevention (ENSLTP) privilege escalation vulnerabilityEPSS 0.2%CVE-2018-6674MEDIUMPrivilege escalation vulnerability in McAfee VSE when McTray run with elevated privilegesEPSS 0.2%CVE-2023-20516LOWImproper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentEPSS 0.2%CVE-2024-0106HIGHNVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper EPSS 0.2%CVE-2023-32494MEDIUM Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker coEPSS 0.2%CVE-2024-46974HIGHGPU DDK - Arbitrary write of read-only dmabufEPSS 0.2%