Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an
On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which a
WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To e
Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions b
VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permissio
Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against ren
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions o
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileg
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or un
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a g
In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. A
Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensit
Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, whic
PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSub
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an aut
Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798.
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35
Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged proc
Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient
Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient
An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation dir
An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installatio
Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Won
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root grou
A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TC
Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by mod
Improper file permissions in the installer for the Intel(R) Media SDK for Windows before version 2019 R1 may allow an au
Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potenti
An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivi
An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature con
The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such a
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to over
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to
Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low pr
In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the Smar
SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, b
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem obje
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could a
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the sessio
An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath vol
In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this partic
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started