CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,885 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 14 of 38
- CVE-2020-0417HIGHCVSS 7.8EG 7.82021-07-14
In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is …
- CVE-2020-0454MEDIUMCVSS 5.5EG 5.52020-11-10
In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of the current SSID with User execution privileges needed. User…
- CVE-2020-0557HIGHCVSS 7.8EG 7.82020-04-15
Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-0559HIGHCVSS 7.8EG 7.82020-08-13
Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-0563HIGHCVSS 7.8EG 7.82020-02-13
Improper permissions in the installer for Intel(R) MPSS before version 3.8.6 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-0668HIGHCVSS 7.8EG 7.82020-02-11
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671,…
- CVE-2020-0805MEDIUMCVSS 5.3EG 5.32020-09-11
<p>A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissi…
- CVE-2020-0904MEDIUMCVSS 6.5EG 6.52020-09-11
<p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already ha…
- CVE-2020-0951MEDIUMCVSS 6.7EG 6.72020-09-11
<p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell c…
- CVE-2020-10088HIGHCVSS 8.1EG 8.12020-03-13
GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.
- CVE-2020-10140HIGHCVSS 7.8EG 7.82020-10-21
Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYST…
- CVE-2020-10513HIGHCVSS 8.8EG 8.82020-04-15
The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the attacker to remotely manipulate arbitrary file.
- CVE-2020-10551HIGHCVSS 7.8EG 7.82020-04-09
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attack…
- CVE-2020-10552HIGHCVSS 8.1EG 8.12021-02-05
An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passw…
- CVE-2020-10553MEDIUMCVSS 5.5EG 5.52021-02-05
An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\Psyprax32\PPScreen.ini contains a hash for the lockscreen (aka screensaver) of the application. If that entry is removed, the lockscreen is no longer displayed and the…
- CVE-2020-1056HIGHCVSS 8.1EG 8.12020-05-21
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack…
- CVE-2020-10642HIGHCVSS 7.8EG 7.82020-04-13
In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker could modify a registry key, which could lead to the execution of malicious code using system privileges when opening RSLinx Classic.
- CVE-2020-10699HIGHCVSS 7.8EG 7.82020-04-15
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration a…
- CVE-2020-10762MEDIUMCVSS 5.5EG 5.52020-11-24
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows …
- CVE-2020-10781MEDIUMCVSS 5.5EG 5.52020-09-16
A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This rea…
- CVE-2020-10782MEDIUMCVSS 6.5EG 6.52020-06-18
An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog configuration file, which has set the wrong world-readable pe…
- CVE-2020-1084MEDIUMCVSS 5.5EG 5.52020-05-21
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values.An attacker who successfully exploited this vulnerability could deny dependent security feature functi…
- CVE-2020-10858MEDIUMCVSS 5.3EG 5.32021-02-05
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
- CVE-2020-10868HIGHCVSS 7.5EG 7.52020-04-01
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to launch the Repair App RPC call from a Low Integrity process.
- CVE-2020-10883HIGHCVSS 7.8EG 7.82020-03-25
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. An attacker must first obtain the ability to execute low-privileged code on the target sys…
- CVE-2020-11107HIGHCVSS 8.8EG 8.82020-04-02
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command …
- CVE-2020-1123MEDIUMCVSS 5.5EG 5.52020-05-21
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is uniqu…
- CVE-2020-11443HIGHCVSS 8.1EG 8.12020-05-04
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this directory, and can write…
- CVE-2020-11467HIGHCVSS 7.2EG 7.22020-04-01
An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-sources theme templates, and uses TWIG as its template engine. Wh…
- CVE-2020-11613HIGHCVSS 7.8EG 7.82020-06-11
Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation folder. By default, the Authenticated Users group has Modify permissions to the installat…
- CVE-2020-1170HIGHCVSS 7.8EG 7.82020-06-09
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevati…
- CVE-2020-11827HIGHCVSS 7.8EG 7.82020-07-14
In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyClientService.exe. After that, the attacker can re-start this…
- CVE-2020-11831CRITICALCVSS 9.8EG 9.82020-11-19
OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.
- CVE-2020-11855HIGHCVSS 7.8EG 7.82020-09-22
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with escalated privileges.
- CVE-2020-11911MEDIUMCVSS 5.3EG 5.32020-06-17
The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.
- CVE-2020-12041CRITICALCVSS 9.4EG 9.42020-06-29
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the …
- CVE-2020-12120HIGHCVSS 7.5EG 7.52020-04-27
The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about …
- CVE-2020-12302HIGHCVSS 7.8EG 7.82020-10-05
Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12431MEDIUMCVSS 6.6EG 6.62020-05-21
A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permissi…
- CVE-2020-12458MEDIUMCVSS 5.5EG 5.52020-04-29
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleart…
- CVE-2020-12459MEDIUMCVSS 5.5EG 5.52020-04-29
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
- CVE-2020-12831MEDIUMCVSS 5.3EG 5.32020-05-13
An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empty config file with world-readable default permissions, leading to a possible information l…
- CVE-2020-12838CRITICALCVSS 9.8EG 9.82020-09-24
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.
- CVE-2020-12839CRITICALCVSS 9.8EG 9.82020-09-24
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.
- CVE-2020-12842CRITICALCVSS 9.8EG 9.82020-09-24
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.
- CVE-2020-12848MEDIUMCVSS 5.4EG 5.42020-06-05
In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in the backend with a random username. An anonymous user that obtains a valid public link can…
- CVE-2020-13125MEDIUMCVSS 6.5EG 6.52020-05-17
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role…
- CVE-2020-13341MEDIUMCVSS 4.9EG 4.92020-10-12
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform various deletions.
- CVE-2020-13386HIGHCVSS 7.3EG 7.32020-05-27
In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the SmartDraw 2020 installation folder. Additionally, when the product is installed, two scheduled tasks are created on the mac…
- CVE-2020-13421CRITICALCVSS 9.8EG 9.82021-04-06
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →