Permissions, Privileges, and Access Controls
Category ID: 264 (Category)Status: Incomplete
+ Description

Description Summary

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
+ Applicable Platforms

Languages

All

+ Potential Mitigations

Follow the principle of least privilege when assigning access rights to entities in a software system.

+ Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
ChildOfCategoryCategory254Security Features
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class250Execution with Unnecessary Privileges
Development Concepts699
ParentOfCategoryCategory265Privilege / Sandbox Issues
Development Concepts (primary)699
ParentOfCategoryCategory275Permission Issues
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class282Improper Ownership Management
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class284Access Control (Authorization) Issues
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class286Incorrect User Management
Development Concepts (primary)699
MemberOfViewView635Weaknesses Used by NVD
Weaknesses Used by NVD (primary)635
CanAlsoBeWeakness BaseWeakness Base283Unverified Ownership
Research Concepts1000
+ Taxonomy Mappings
Mapped Taxonomy NameNode IDFitMapped Node Name
PLOVERPermissions, Privileges, and ACLs
+ Related Attack Patterns
CAPEC-IDAttack Pattern Name
(CAPEC Version: 1.4)
5Analog In-band Switching Signals (aka Blue Boxing)
17Accessing, Modifying or Executing Executable Files
35Leverage Executable Code in Nonexecutable Files
58Restful Privilege Elevation
69Target Programs with Elevated Privileges
76Manipulating Input to File System Calls
+ References
[REF-11] M. Howard and D. LeBlanc. "Writing Secure Code". Chapter 7, "How Tokens, Privileges, SIDs, ACLs, and Processes Relate" Page 218. 2nd Edition. Microsoft. 2002.
+ Content History
Submissions
Submission DateSubmitterOrganizationSource
PLOVERExternally Mined
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Relationships, Taxonomy Mappings