CWE-264: Permissions, Privileges, and Access Controls
Permissions, Privileges, and Access Controls
Category ID: 264 (Category)
Status: Incomplete
Description
Description Summary
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Applicable Platforms
Languages
All
Potential Mitigations
Phase: Architecture and Design
Strategy: Separation of Privilege
Follow the principle of least privilege when assigning access rights
to entities in a software system.
[REF-11] M. Howard and
D. LeBlanc. "Writing Secure Code". Chapter 7, "How Tokens, Privileges, SIDs, ACLs, and Processes
Relate" Page 218. 2nd Edition. Microsoft. 2002.