← Back
CWE-269

2,777 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (2,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Discourse
1Discourse
Nov 21, 2024
Dec 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed,...Show more
Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of DiscourseShow less
1Microsoft
1Windows 10 Update Assistant
Nov 21, 2024
Nov 24, 2021
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
Windows 10 Update Assistant Elevation of Privilege Vulnerability
1Kaspersky
1Password Manager
Nov 21, 2024
Nov 23, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
2Fedoraproject
Xen
2Fedora
Xen
Nov 21, 2024
Nov 21, 2021
N/A· v4
8.8 HIGH· v3
6.9 MEDIUM· v2
certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-...Show more
certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-level translation (EPT), and IOMMUs. These page tables are presently set up to always be 4 levels deep. However, an IOMMU may require the use of just 3 page table levels. In such a configuration the lop level table needs to be stripped before inserting the root table's address into the hardware pagetable base register. When sharing page tables, Xen erroneously skipped this stripping. Consequently, the guest is able to write to leaf page table entries.Show less
1Dell
1Networking Os10
Nov 21, 2024
Nov 20, 2021
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low privileged user with specific access to the API could potentially exploit this vul...Show more
Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low privileged user with specific access to the API could potentially exploit this vulnerability to gain admin privileges on the affected system.Show less
1Gallagher
1Command Centre
Nov 21, 2024
Nov 18, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue aff...Show more
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ; 8.40 versions prior to 8.40.2063 (MR4); 8.30 versions prior to 8.30.1454 (MR4) ; 8.20 versions prior to 8.20.1291 (MR6); version 8.10 and prior versions.Show less
1Hitachienergy
5Gms600 Firmware
Pwc600 FirmwareRelion 650 Firmware+2 more
Nov 21, 2024
Nov 18, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of w...Show more
Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to an internal database tables, could allow anybody with user credentials to bypass security controls that is enforced by the product. Consequently, exploitation may lead to unauthorized modifications on data/firmware, and/or to permanently disabling the product. This issue affects: Hitachi Energy Relion 670 Series 2.0 all revisions; 2.2.2 all revisions; 2.2.3 versions prior to 2.2.3.5. Hitachi Energy Relion 670/650 Series 2.1 all revisions. 2.2.0 all revisions; 2.2.4 all revisions; Hitachi Energy Relion 670/650/SAM600-IO 2.2.1 all revisions; 2.2.5 versions prior to 2.2.5.2. Hitachi Energy Relion 650 1.0 all revisions. 1.1 all revisions; 1.2 all revisions; 1.3 versions prior to 1.3.0.8; Hitachi Energy GMS600 1.3.0; 1.3.0.1; 1.2.0. Hitachi Energy PWC600 1.0.1 version 1.0.1.4 and prior versions; 1.1.0 version 1.1.0.1 and prior versions.Show less
1Elastic
1Kibana
Nov 21, 2024
Nov 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host...Show more
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this vulnerability.Show less
1Zoho
1Manageengine Remote Access Plus Server
Nov 21, 2024
Nov 17, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user...Show more
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive information including DB Connection string, entire IT infrastructure details, commands executed by IT admin including credentials, secrets, private keys and more.Show less
1Microsoft
1Visual Studio Code
Nov 21, 2024
Nov 10, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Visual Studio Code Elevation of Privilege Vulnerability
1Microsoft
2Visual Studio 2017
Visual Studio 2019
Nov 21, 2024
Nov 10, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Visual Studio Elevation of Privilege Vulnerability
1Microsoft
1Azure Real Time Operating System
Nov 21, 2024
Nov 10, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Azure RTOS Elevation of Privilege Vulnerability
1Microsoft
1Azure Real Time Operating System
Nov 21, 2024
Nov 10, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Azure RTOS Elevation of Privilege Vulnerability
1Microsoft
1Azure Real Time Operating System
Nov 21, 2024
Nov 10, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Azure RTOS Elevation of Privilege Vulnerability
1Microsoft
6Windows Server
Windows Server 2008Windows Server 2012+3 more
Nov 21, 2024
Nov 10, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Active Directory Domain Services Elevation of Privilege Vulnerability
1Microsoft
3Windows 10
Windows ServerWindows Server 2016
Nov 21, 2024
Nov 10, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
1Microsoft
11Windows 10
Windows 11Windows 7+8 more
Nov 21, 2024
Nov 10, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Nov 21, 2024
Nov 10, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NTFS Elevation of Privilege Vulnerability
1Microsoft
6Windows Server
Windows Server 2008Windows Server 2012+3 more
Nov 21, 2024
Nov 10, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Active Directory Domain Services Elevation of Privilege Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Nov 21, 2024
Nov 10, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Feedback Hub Elevation of Privilege Vulnerability