CWE-269
2,777 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,777)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed,...Show more |
1Microsoft 1Windows 10 Update Assistant Nov 21, 2024 Nov 24, 2021 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 Windows 10 Update Assistant Elevation of Privilege Vulnerability |
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High. |
certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-...Show more |
Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low privileged user with specific access to the API could potentially exploit this vul...Show more |
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue aff...Show more |
1Hitachienergy 5Gms600 Firmware Pwc600 FirmwareRelion 650 Firmware+2 moreNov 21, 2024 Nov 18, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of w...Show more |
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host...Show more |
1Zoho 1Manageengine Remote Access Plus Server Nov 21, 2024 Nov 17, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user...Show more |
1Microsoft 1Visual Studio Code Nov 21, 2024 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Visual Studio Code Elevation of Privilege Vulnerability |
1Microsoft 2Visual Studio 2017 Visual Studio 2019Nov 21, 2024 Nov 10, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Visual Studio Elevation of Privilege Vulnerability |
1Microsoft 1Azure Real Time Operating System Nov 21, 2024 Nov 10, 2021 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Azure RTOS Elevation of Privilege Vulnerability |
1Microsoft 1Azure Real Time Operating System Nov 21, 2024 Nov 10, 2021 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Azure RTOS Elevation of Privilege Vulnerability |
1Microsoft 1Azure Real Time Operating System Nov 21, 2024 Nov 10, 2021 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Azure RTOS Elevation of Privilege Vulnerability |
1Microsoft 6Windows Server Windows Server 2008Windows Server 2012+3 moreNov 21, 2024 Nov 10, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Active Directory Domain Services Elevation of Privilege Vulnerability |
1Microsoft 3Windows 10 Windows ServerWindows Server 2016Nov 21, 2024 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability |
1Microsoft 11Windows 10 Windows 11Windows 7+8 moreNov 21, 2024 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Kernel Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreNov 21, 2024 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NTFS Elevation of Privilege Vulnerability |
1Microsoft 6Windows Server Windows Server 2008Windows Server 2012+3 moreNov 21, 2024 Nov 10, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Active Directory Domain Services Elevation of Privilege Vulnerability |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreNov 21, 2024 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Feedback Hub Elevation of Privilege Vulnerability |