Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-250 (带着不必要的权限执行) — Vulnerability Class 280

280 vulnerabilities classified as CWE-250 (带着不必要的权限执行). AI Chinese analysis included.

CWE-250 represents a critical architectural weakness where software executes operations using elevated privileges beyond what is strictly necessary for the task. This misconfiguration typically allows attackers to exploit other vulnerabilities, such as buffer overflows or injection flaws, by granting them higher-level access than intended. If an attacker compromises a low-privilege component, the excessive permissions amplify the impact, potentially leading to full system compromise or unauthorized data modification. To mitigate this risk, developers must adhere to the principle of least privilege, ensuring that each process or user account operates with only the minimum permissions required for its specific function. Implementing strict access controls, regularly auditing permission assignments, and isolating services further reduce the attack surface, thereby limiting the potential damage from any single security breach.

MITRE CWE Description
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Common Consequences (1)
Confidentiality, Integrity, Availability, Access Control Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands, Read Application Data, DoS: Crash, Exit, or Restart
An attacker will be able to gain access to any resources that are allowed by the extra privileges. Common results include executing code, disabling services, and reading restricted data. New weaknesses can be exposed because running with extra privileges, such as root or Administrator, can disable t…
Mitigations (5)
Architecture and Design, Operation Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database ad…
Architecture and Design Identify the functionality that requires additional privileges, such as access to privileged operating system resources. Wrap and centralize this functionality if possible, and isolate the privileged code as much as possible from other code [REF-76]. Raise privileges as late as possible, and drop them as soon as possible to avoid CWE-271. Avoid weaknesses such as CWE-288 and CWE-420 by protecting …
Architecture and Design Identify the functionality that requires additional privileges, such as access to privileged operating system resources. Wrap and centralize this functionality if possible, and isolate the privileged code as much as possible from other code [REF-76]. Raise privileges as late as possible, and drop them as soon as possible to avoid CWE-271. Avoid weaknesses such as CWE-288 and CWE-420 by protecting …
Implementation Perform extensive input validation for any privileged code that must be exposed to the user and reject anything that does not fit your strict requirements.
Implementation When dropping privileges, ensure that they have been dropped successfully to avoid CWE-273. As protection mechanisms in the environment get stronger, privilege-dropping calls may fail even if it seems like they would always succeed.
Examples (2)
This code temporarily raises the program's privileges to allow creation of a new user folder.
def makeNewUserDir(username): if invalidUsername(username): #avoid CWE-22 and CWE-78 print('Usernames cannot contain invalid characters') return False try: raisePrivileges() os.mkdir('/home/' + username) lowerPrivileges() except OSError: print('Unable to create new user directory for user:' + username) return False return True
Bad · Python
The following code calls chroot() to restrict the application to a subset of the filesystem below APP_HOME in order to prevent an attacker from using the program to gain unauthorized access to files located elsewhere. The code then opens a file specified by the user and processes the contents of the file.
chroot(APP_HOME); chdir("/"); FILE* data = fopen(argv[1], "r+"); ...
Bad · C
CVE ID Title CVSS Severity Published
CVE-2024-28140 Violation of Least Privilege Principle — Scan2Net 9.8 - 2024-12-11
CVE-2024-28139 Privilege escalation through sudo misconfiguration — Scan2Net 7.8 - 2024-12-11
CVE-2024-49804 IBM Security Verify Access Appliance privilege escalation — Security Verify Access 7.8 High 2024-11-29
CVE-2021-38118 Possible Local Privilege Escalation Vulnerability in OpenText iManager — iManager 5.5 Medium 2024-11-22
CVE-2024-52799 Argo Workflows Chart: Excessive Privileges in Workflow Role — argo-helm 8.3 High 2024-11-21
CVE-2024-11075 SICK Incoming Goods Suite privilege escalation vulnerability — SICK Incoming Goods Suite 8.8 High 2024-11-19
CVE-2020-26074 Cisco SD-WAN vManage Privilege Escalation Vulnerability — Cisco Catalyst SD-WAN Manager 7.8 High 2024-11-18
CVE-2024-8781 Container Escape Vulnerability in TR7's Application Security Platform (ASP) — Application Security Platform (ASP) 7.8AI High AI 2024-11-18
CVE-2024-51722 Vulnerabilities in SecuSUITE Server Components Impact SecuSUITE — SecuSUITE 6.4 Medium 2024-11-12
CVE-2024-48837 Dell SmartFabric OS10 安全漏洞 — SmartFabric OS10 Software 7.8 High 2024-11-12
CVE-2024-47903 Siemens InterMesh 7177和Siemens InterMesh 7707 安全漏洞 — InterMesh 7177 Hybrid 2.0 Subscriber 5.8 Medium 2024-10-23
CVE-2024-20420 Cisco ATA 190 Series Analog Telephone Adapter Firmware Privilege Escalation Vulnerability — Cisco Analog Telephone Adaptor (ATA) Software 5.4 Medium 2024-10-16
CVE-2024-9473 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability — GlobalProtect App 7.8AI High AI 2024-10-09
CVE-2024-43583 Winlogon Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High 2024-10-08
CVE-2024-8903 Acronis Cyber Protect Cloud Agent 安全漏洞 — Acronis Cyber Protect Cloud Agent 7.8AI High AI 2024-09-23
CVE-2024-8767 Acronis多款产品 安全漏洞 — Acronis Backup plugin for cPanel & WHM 8.8 - 2024-09-17
CVE-2024-7387 Openshift/builder: path traversal allows command injection in privileged buildcontainer using docker build strategy 9.1 Critical 2024-09-16
CVE-2024-35783 Siemens SIMATIC 安全漏洞 — SIMATIC BATCH V9.1 9.1 Critical 2024-09-10
CVE-2024-45034 Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes — Apache Airflow 7.8 - 2024-09-07
CVE-2024-5623 Untrusted search path vulnerability in B&R APROL — B&R APROL 7.3AI High AI 2024-08-29
CVE-2024-5622 Untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL — B&R APROL 7.8AI High AI 2024-08-29
CVE-2024-20478 Cisco Application Policy Infrastructure Controller App Privilege Escalation Vulnerability — Cisco Application Policy Infrastructure Controller (APIC) 6.5 Medium 2024-08-28
CVE-2024-36398 Siemens SINEC NMS 安全漏洞 — SINEC NMS 7.8 High 2024-08-13
CVE-2024-6913 Execution with Unnecessary Privileges — ProcessPlus 9.8AI Critical AI 2024-07-22
CVE-2024-20435 Cisco AsyncOS 安全漏洞 — Cisco Secure Web Appliance 8.8 High 2024-07-17
CVE-2024-35154 IBM WebSphere Application Server code execution — WebSphere Application Server 7.2 High 2024-07-09
CVE-2024-32853 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS 4.4 Medium 2024-07-02
CVE-2023-30997 IBM Security Access Manager Docker privilege escalation — Security Access Manager Docker 7.8 High 2024-06-27
CVE-2023-30998 IBM Security Access Manager Docker privilege escalation — Security Access Manager Docker 7.8 High 2024-06-27
CVE-2024-31890 IBM i privilege escalation — i 7.8 High 2024-06-21

Vulnerabilities classified as CWE-250 (带着不必要的权限执行) represent 280 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.