COMMON WEAKNESS ENUMERATIONDraft

CWE-266

Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Soyutlama

Base

Yapı

Simple

Sömürü İhtimali

Medium

Problemi anla

Problem nedir?

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Kök neden

Problem nasıl ve ne zaman oluşur?

Yaşam döngüsü evresi

Implementation

REALIZATION: This weakness is caused during implementation of an architectural security tactic.

Risk

Başarılı sömürü neye yol açar?

Gain Privileges or Assume Identity

Etkilenen güvenlik alanları: Access Control

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Savunma

Nasıl önlenir ve çözülür?

Architecture and Design · Operation

Birden fazla yaşam döngüsü evresinde uygulanacak savunma

Detay
Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.

Architecture and Design · Operation

Environment Hardening

Detay
Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.