The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.