CVEbaza.plSłownik CWECWE-273
Common Weakness Enumeration

CWE-273

Improper Check for Dropped Privileges

Kategoria: BaseCVE: 49
Opis

Produkt podejmuje próbę ograniczenia uprawnień, ale nie sprawdza lub nieprawidłowo sprawdza, czy operacja się powiodła. Brak weryfikacji może prowadzić do utrzymania nieoczekiwanych uprawnień dostępu.

Description (EN)

The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.

Podatności CVE z CWE-273 (49)
10.0
CVSS
HIGH
CVE-2015-0278

libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

pub. 2015-05-18
9.8
CVSS
CRITICAL
CVE-2023-34844

Play With Docker w wersji poniżej 0.0.2 uruchamia kontenery w niebezpiecznym trybie uprzywilejowanym CAP_SYS_ADMIN, co umożliwia ucieczkę z izolacji kontenera Docker. Jest to krytyczna podatność pozwalająca atakującemu na przejęcie kontroli nad systemem hosta.

pub. 2023-06-29
9.8
CVSS
CRITICAL
CVE-2021-36372

W Apache Ozone przed wersją 1.2.0 pierwotnie wygenerowane block tokeny są utrwalane w bazie metadanych i mogą być pobrane przez uwierzytelnionych użytkowników posiadających uprawnienia do klucza. Krytyczność wynika z faktu, że tokeny pozostają użyteczne nawet po cofnięciu dostępu użytkownikowi.

pub. 2021-11-19
9.8
CVSS
CRITICAL
CVE-2020-24361

SNMPTT przed wersją 1.4.2 zawiera krytyczną podatność umożliwiającą atakującym wykonanie dowolnego kodu powłoki (shell code) za pośrednictwem mechanizmów EXEC, PREXEC lub unknown_trap_exec. Brak uwierzytelnienia i sieciowy wektor ataku czynią tę podatność szczególnie niebezpieczną.

pub. 2020-08-16
9.8
CVSS
CRITICAL
CVE-2011-2921

ktsuss w wersjach 1.4 i wcześniejszych posiada ustawiony UID na root i nie zrzuca uprawnień przed wykonaniem poleceń wskazanych przez użytkownika. Pozwala to na uruchamianie dowolnych poleceń z uprawnieniami root przez nieuprzywilejowanego użytkownika.

pub. 2019-11-19
9.8
CVSS
CRITICAL
CVE-2011-3350

Masqmail w wersjach 0.2.21–0.2.30 nieprawidłowo wywołuje funkcję seteuid() w plikach src/log.c i src/masqmail.c, co skutkuje niewłaściwym obniżaniem uprawnień procesu. Błąd może pozwolić na wykonanie operacji z nienależnymi uprawnieniami, co stanowi poważne zagrożenie dla bezpieczeństwa systemu.

pub. 2019-11-19
9.8
CVSS
CRITICAL
CVE-2012-1187

BitlBee nie usuwa poprawnie dodatkowych uprawnień grupowych w pliku unix.c, co może prowadzić do nieautoryzowanego podniesienia uprawnień. Podatność otrzymała krytyczny poziom CVSS 9.8, co wskazuje na możliwość jej zdalnego wykorzystania bez uwierzytelnienia.

pub. 2019-10-29
9.8
CVSS
CRITICAL
CVE-2017-6972

AlienVault USM, OSSIM oraz NfSen nieprawidłowo porzucają uprawnienia roota podczas wykonywania kodu Perl komponentu NfSen, co prowadzi do uruchamiania go z najwyższymi uprawnieniami systemowymi. Podatność jest krytyczna ze względu na możliwość wykonywania operacji z pełnym dostępem do systemu.

pub. 2017-03-22
8.8
CVSS
HIGH
CVE-2026-32107

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.

pub. 2026-04-17
8.8
CVSS
HIGH
CVE-2024-8382

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

pub. 2024-09-03
8.8
CVSS
HIGH
CVE-2020-14298

The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This issue only affects docker version 1.13.1-108.git4ef4b30.el7, shipped in Red Hat Enterprise Linux 7 Extras. Both earlier and later versions are not affected.

pub. 2020-07-13
8.8
CVSS
HIGH
CVE-2020-14300

The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compromise a process entering container namespace and execute arbitrary code outside of the container. This could lead to compromise of the container host or other containers running on the same container host. This issue only affects a single version of Docker, 1.13.1-108.git4ef4b30, shipped in Red Hat Enterprise Linux 7. Both earlier and later versions are not affected.

pub. 2020-07-13
8.7
CVSS
HIGH
CVE-2026-60085

PraisonAI przed wersją 4.6.78 zawiera podatność polegającą na całkowitym ignorowaniu skonfigurowanych ograniczeń bezpieczeństwa w domyślnym backendzie Subprocess Sandbox. Atakujący może wykonywać dowolne polecenia systemowe, odczytywać wrażliwe pliki oraz przeprowadzać destrukcyjne operacje, pomimo jawnie skonfigurowanej polityki bezpieczeństwa.

pub. 2026-07-15
8.7
CVSS
HIGH
CVE-2025-27396

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit the elevation of privileges required to perform certain valid functionality. This could allow an authenticated lowly-privileged remote attacker to escalate their privileges.

pub. 2025-03-11
8.5
CVSS
HIGH
CVE-2025-1003

A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass which may result in escalation of privilege. HP is releasing a software update to mitigate this potential vulnerability.

pub. 2025-02-04
8.4
CVSS
HIGH
CVE-2026-21882

theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping allows local privilege escalation via command re-execution. This issue has been patched in version 0.2.0.

pub. 2026-03-02
8.1
CVSS
HIGH
CVE-2018-16466

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.

pub. 2018-10-30
7.9
CVSS
HIGH
CVE-2026-54552

sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but can retain the parent process's supplementary groups because the privilege-drop sequence does not fully establish the target user's UID, primary GID, and supplementary groups. The child can therefore retain access to files or resources granted to privileged groups such as root, docker, disk, shadow, or sudo, violating the expected _uid privilege boundary. This issue is fixed in version 2.2.4.

pub. 2026-08-18
7.8
CVSS
HIGH
CVE-2026-61897

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.

pub. 2026-08-20
7.8
CVSS
HIGH
CVE-2026-0099

In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

pub. 2026-06-01
Pokazano 20 z 49 podatności
Informacje
ID: CWE-273
Typ: Base
Podatności: 49
MITRE CWE ↗
← Słownik CWE