Weakness
Permissions, Privileges, and Access Controls
CWE-264 · Category
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
◆
ATT&CK Techniques
13Adversary techniques associated with this weakness, via MITRE CAPEC and authoritative CTID CVE mappings.
T1059.001PowerShell
T1078Valid Accounts
T1078.003Local Accounts
T1087Account Discovery
T1136Create Account
T1499.004Application or System Exploitation
T1608Stage Capabilities
⚠
CVEs With This Weakness
5,488A sample of the 5,488 CVEs tagged with this weakness.
View all 5,488 CVEs with this weakness
◉
Nuclei Scanner Templates
8Open-source Nuclei templates that detect this weakness class - an actionable scan-for-it pivot. Licensed under the ProjectDiscovery / Nuclei terms.
criticalZTE Cable Modem Web Shell
External lookups - second-class, for what we don’t hold ourselves