CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 24 of 34
- CVE-2024-20005HIGHCVSS 8.2EG 8.22024-03-04
In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS083555…
- CVE-2024-20671MEDIUMCVSS 5.5EG 5.52024-03-12
Microsoft Defender Security Feature Bypass Vulnerability
- CVE-2024-20830MEDIUMCVSS 5.3EG 5.32024-03-05
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
- CVE-2024-20841MEDIUMCVSS 5.1EG 5.12024-03-05
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.
- CVE-2024-20921MEDIUMCVSS 5.9EG 5.92024-02-17
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21…
- CVE-2024-21002LOWCVSS 2.5EG 2.52024-04-16
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. …
- CVE-2024-21004LOWCVSS 2.5EG 2.52024-04-16
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. …
- CVE-2024-21012LOWCVSS 3.7EG 3.72024-04-16
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.22, 17.0.10, 21.0.2, 22; Oracl…
- CVE-2024-21116HIGHCVSS 7.8EG 7.82024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
- CVE-2024-21122MEDIUMCVSS 5.4EG 5.42024-07-16
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with …
- CVE-2024-21123LOWCVSS 2.3EG 2.32024-07-16
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the…
- CVE-2024-21615MEDIUMCVSS 5.0EG 5.02024-04-12
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access confidential information on the system. On all Junos OS and Junos OS Evolved platforms, whe…
- CVE-2024-2175HIGHCVSS 7.8EG 7.82024-08-16
An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges.
- CVE-2024-21820HIGHCVSS 7.2EG 7.22024-11-13
Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2024-21840HIGHCVSS 7.9EG 7.92024-01-30
Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.
- CVE-2024-21937HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21938HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary co…
- CVE-2024-21939HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21945HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21946HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21957HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21958HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2024-21960HIGHCVSS 7.3EG 7.32025-05-13
Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-22062MEDIUMCVSS 6.3EG 6.32024-07-09
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
- CVE-2024-22085MEDIUMCVSS 6.2EG 6.22024-03-20
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.
- CVE-2024-22301MEDIUMCVSS 5.3EG 5.32024-01-24
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On line: from n/a through 4.6.6.
- CVE-2024-22378MEDIUMCVSS 6.7EG 6.72024-08-14
Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-22385MEDIUMCVSS 4.4EG 4.42024-06-25
Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.
- CVE-2024-22409HIGHCVSS 7.5EG 7.52024-01-16
DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user's profile information. The default privileges gave too many broad permissions to low priv…
- CVE-2024-22428HIGHCVSS 7.0EG 7.02024-01-16
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommen…
- CVE-2024-22430MEDIUMCVSS 5.5EG 5.52024-02-01
Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service.
- CVE-2024-22889HIGHCVSS 7.5EG 7.52024-03-06
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
- CVE-2024-23201MEDIUMCVSS 5.5EG 6.22024-03-08
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able to cause a denial-…
- CVE-2024-23253HIGHCVSS 3.3EG 7.52024-03-08
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.
- CVE-2024-23295MEDIUMCVSS 5.5EG 6.22024-03-08
A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.
- CVE-2024-23301MEDIUMCVSS 5.5EG 5.52024-01-12
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
- CVE-2024-23495MEDIUMCVSS 6.7EG 6.72024-08-14
Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-23847MEDIUMCVSS 5.9EG 5.92024-05-31
Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered o…
- CVE-2024-23974MEDIUMCVSS 6.7EG 6.72024-08-14
Incorrect default permissions in some Intel(R) ISH software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-24828MEDIUMCVSS 6.6EG 6.62024-02-09
pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On unix systems, this is `/tmp/pkg/*` which is a shared directory for all users on the same lo…
- CVE-2024-25605MEDIUMCVSS 5.3EG 5.32024-02-20
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web…
- CVE-2024-25647MEDIUMCVSS 6.7EG 6.72024-11-13
Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-25654MEDIUMCVSS 5.5EG 5.52024-03-18
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensit…
- CVE-2024-25958MEDIUMCVSS 6.7EG 6.72024-03-26
Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege escalation, unauthorize…
- CVE-2024-26025MEDIUMCVSS 6.7EG 6.72024-08-14
Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-26280MEDIUMCVSS 4.7EG 4.72024-03-01
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names and usernames they were not permitted to view. With 2.8.2 and newer, Ops…
- CVE-2024-26302MEDIUMCVSS 4.8EG 4.82024-02-27
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve informat…
- CVE-2024-26574HIGHCVSS 7.8EG 7.82024-04-08
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe
- CVE-2024-27134HIGHCVSS 7.0EG 7.02024-11-25
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when t…
- CVE-2024-27144CRITICALCVSS 9.8EG 9.82024-06-14
The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. …
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →