CWE-250
338 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CVEs (338)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by exploiting a system level service. An attacker could leverage this vulnerability to escalate privileg...Show more |
1Illumina 1Local Run Manager Jun 17, 2026 Jun 24, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access...Show more |
1Bosch 1Pra Es8p2s Firmware Jun 17, 2026 Jun 23, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch. |
Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3. |
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 |
1Bender 2Cc612 Firmware Icc15xx FirmwareJun 17, 2026 Apr 27, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd. |
Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target JVM process. This would allow a container to exhaust the resources of th...Show more |
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotp...Show more |
Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing restrictions set on the container. |
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges. |
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root-level privileges. This vulnerability is due...Show more |
1Sick 1Overall Equipment Effectiveness Jun 17, 2026 Apr 11, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content. |
1Acronis 4Agent Cyber ProtectCyber Protect Home Office+1 moreJun 17, 2026 Feb 4, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147,...Show more |
1Dell 7Powermax Os Solutions EnablerSolutions Enabler Virtual Appliance+4 moreJun 17, 2026 Jan 21, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance. |
3Debian FedoraprojectIpython3Debian Linux FedoraIpythonJun 17, 2026 Jan 19, 2022 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code ex...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker must first obtain the ability to execute low-privileged code on the target...Show more |
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to execute privileged operations by the guest OS, which may lead to information disclosure, data tamper...Show more |
1Bitdefender 2Endpoint Security Tools Total SecurityJun 17, 2026 Oct 28, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT AUTHORITY\System. Impersonation enables the server thread to perform ac...Show more |
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. |
1Siemens 10Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Rx1400 FirmwareRuggedcom Rox Rx1500 Firmware+7 moreJun 17, 2026 Sep 14, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2....Show more |