CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337 vulnerabilities with CWE-281
CVE-2017-8552 HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.8
CVE-2017-8543 CRITICAL KEV
Microsoft Windows - Remote Code Execution via Windows Search Memory Handling
CVSS 9.8
CVE-2017-8494 HIGH
Microsoft Windows <10 Gold-1703 - Privilege Escalation
CVSS 7.3
CVE-2017-8468 HIGH
Windows 8.1/10, Server 2012 R2/2016 - Elevation of Privilege via Win32k
CVSS 7.8
CVE-2017-8466 HIGH
Windows Cursor - Privilege Escalation via Improper Permission Preservation
CVSS 7.8
CVE-2017-8465 HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.8
CVE-2017-5033 MEDIUM
Google Chrome <57.0.2987.98-57.0.2987.108 - XSS
CVSS 4.3
CVE-2013-6335
IBM Tivoli Storage Manager - Info Disclosure
CVE-2005-1920 HIGH
KDE 3.2.x-3.4.0 - Improper Preservation of Permissions in Kate and Kwrite Backup Files
CVSS 7.5
CVE-2002-2323 HIGH
Sun PC NetLink 1.0-1.2 - Improper Preservation of Permissions via Symbolic Link Handling
CVSS 7.5
CVE-2001-1515 HIGH
Windows 2000 SP1 - Privilege Escalation
CVSS 7.5
CVE-2001-0195 HIGH
Debian sash < 3.4-4 - Improper Preservation of Permissions
CVSS 7.8
Details
Vulnerabilities 337