CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,721 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 11 of 35
- CVE-2022-4569HIGHCVSS 7.8EG 7.82023-06-05
A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.
- CVE-2023-29733HIGHCVSS 7.8EG 7.82023-05-30
The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issue…
- CVE-2023-29838HIGHCVSS 7.8EG 7.82023-05-22
Insecure Permission vulnerability found in Botkind/Siber Systems SyncApp v.19.0.3.0 allows a local attacker toe escalate privileges via the SyncService.exe file.
- CVE-2023-33240HIGHCVSS 7.8EG 7.82023-05-19
Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when in…
- CVE-2022-45452HIGHCVSS 7.8EG 7.82023-05-18
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984.
- CVE-2023-21107HIGHCVSS 7.8EG 7.82023-05-15
In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local escalation of privilege across user boundaries with no additional execution privileges needed. User interaction is not nee…
- CVE-2022-38583HIGHCVSS 7.8EG 7.82023-04-28
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstation user could abuse their access to the "SharedData" folde…
- CVE-2022-31244HIGHCVSS 7.8EG 7.82023-04-25
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
- CVE-2021-41614HIGHCVSS 7.8EG 7.82023-04-18
An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to the Exception Program Counter Register (EPCR) are not implemented correctly. User programs from an unauthorized privilege…
- CVE-2023-28966HIGHCVSS 7.8EG 7.82023-04-17
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modify existing files or execute commands as root. The issue is caused by improper file and dir…
- CVE-2023-25941HIGHCVSS 7.8EG 7.82023-04-04
Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and inform…
- CVE-2023-21433HIGHCVSS 7.8EG 7.82023-02-09
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.
- CVE-2022-31254HIGHCVSS 7.8EG 7.82023-02-07
A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows …
- CVE-2022-23454HIGHCVSS 7.8EG 7.82023-02-01
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of fi…
- CVE-2022-23453HIGHCVSS 7.8EG 7.82023-02-01
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of fi…
- CVE-2022-45099HIGHCVSS 7.8EG 7.82023-02-01
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise
- CVE-2022-47040HIGHCVSS 7.8EG 7.82023-01-26
An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after placing a crafted file in the /tmp directory and sending crafted packets through port 80.
- CVE-2022-20456HIGHCVSS 7.8EG 7.82023-01-26
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
- CVE-2022-3155HIGHCVSS 7.8EG 7.82022-12-22
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started i…
- CVE-2022-20611HIGHCVSS 7.8EG 7.82022-12-13
In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges nee…
- CVE-2022-20495HIGHCVSS 7.8EG 7.82022-12-13
In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr…
- CVE-2022-20475HIGHCVSS 7.8EG 7.82022-12-13
In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges neede…
- CVE-2022-20474HIGHCVSS 7.8EG 7.82022-12-13
In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
- CVE-2022-1038HIGHCVSS 7.8EG 7.82022-12-12
A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.
- CVE-2022-42718HIGHCVSS 7.8EG 7.82022-12-01
Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-20452HIGHCVSS 7.8EG 7.82022-11-08
In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti…
- CVE-2022-20441HIGHCVSS 7.8EG 7.82022-11-08
In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additiona…
- CVE-2022-33182HIGHCVSS 7.8EG 7.82022-10-25
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “…
- CVE-2022-36438HIGHCVSS 7.8EG 7.82022-10-18
AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface…
- CVE-2022-20436HIGHCVSS 7.8EG 7.82022-10-11
There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242248369
- CVE-2022-20435HIGHCVSS 7.8EG 7.82022-10-11
There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission protection, resulting in EoP problem.Product: AndroidVersions: Android SoCAndroid ID: A-2…
- CVE-2022-26235HIGHCVSS 7.8EG 7.82022-10-06
A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Remisol Advance allow non-privileged users to overwrite and/or manipulate executables and lib…
- CVE-2022-3263HIGHCVSS 7.8EG 7.82022-09-23
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.
- CVE-2022-38764HIGHCVSS 7.8EG 7.82022-09-19
A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer.
- CVE-2022-38466HIGHCVSS 7.8EG 7.82022-09-13
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator.
- CVE-2022-2735HIGHCVSS 7.8EG 7.82022-09-06
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for…
- CVE-2022-37173HIGHCVSS 7.8EG 7.82022-08-30
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
- CVE-2022-26344HIGHCVSS 7.8EG 7.82022-08-18
Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-30490HIGHCVSS 7.8EG 7.82022-08-16
upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.
- CVE-2022-20281HIGHCVSS 7.8EG 7.82022-08-12
In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…
- CVE-2022-20246HIGHCVSS 7.8EG 7.82022-08-11
In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check. This could lead to local escalation of privilege with no additional execution privileges…
- CVE-2022-20360HIGHCVSS 7.8EG 7.82022-08-10
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed f…
- CVE-2022-20349HIGHCVSS 7.8EG 7.82022-08-10
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution pr…
- CVE-2022-20348HIGHCVSS 7.8EG 7.82022-08-10
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileg…
- CVE-2022-37030HIGHCVSS 7.8EG 7.82022-08-04
Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the gromox group to have the PAM stack execute arbitrary code upon loading the Gromox PAM modul…
- CVE-2022-26429HIGHCVSS 7.8EG 7.82022-08-01
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2022-33912HIGHCVSS 7.8EG 7.82022-06-17
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer sc…
- CVE-2022-31500HIGHCVSS 7.8EG 7.82022-06-02
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
- CVE-2022-29483HIGHCVSS 7.8EG 7.82022-06-02
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
- CVE-2022-30594HIGHCVSS 7.8EG 7.82022-05-12
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →