CWE-732
1,702 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CVEs (1,702)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM. |
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions. |
The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the application, he could get access to the session cookie. The session cook...Show more |
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service to exploit this vulne...Show more |
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does n...Show more |
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control access for Everyone, and leading to privilege escalation because of a St...Show more |
1Cisco 1Adaptive Security Appliance Software Jun 17, 2026 Aug 7, 2019 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file w...Show more |
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access. |
1Pivotal Software 3Application Service Cloud Foundry UaaOperations ManagerJun 17, 2026 Aug 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' an...Show more |
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308). |
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). |
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). |
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432). |
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430). |
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429). |
cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427). |
In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890). |
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494). |
1Ibm 1Qradar Security Information And Event Manager Nov 21, 2024 Jul 22, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 155350. |
Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executabl...Show more |