CWE-271: Privilege Dropping / Lowering Errors

ClassIncompleteExploit Likelihood: High

The product does not drop privileges before passing control of a resource to an actor that does not have those privileges.

View on MITRE
Back to CWE Lookup

Extended Description

In some contexts, a system executing with elevated permissions will hand off a process/file/etc. to another process or user. If the privileges of an entity are not reduced, then elevated privileges are spread throughout a system and possibly to an attacker.

Technical Details

Structure
Simple

Applicable To

Languages
Not Language-Specific
Platforms

Learn More