← Back
CWE-269

2,777 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (2,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Johnsoncontrols
1Exacqvision Web Service
Nov 21, 2024
Oct 11, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
1Hashicorp
1Vault
Nov 21, 2024
Oct 11, 2021
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than inte...Show more
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.Show less
1Cisco
1Smart Software Manager On Prem
Nov 21, 2024
Oct 6, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and create, read, update, or delete records and settings in multiple...Show more
A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and create, read, update, or delete records and settings in multiple functions. This vulnerability is due to insufficient authorization of the System User and System Operator role capabilities. An attacker could exploit this vulnerability by directly accessing a web resource. A successful exploit could allow the attacker to create, read, update, or delete records and settings in multiple functions without the necessary permissions on the web UI.Show less
1Google
1Android
Nov 21, 2024
Oct 6, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privi...Show more
In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-188554048Show less
3Debian
FedoraprojectXen
3Debian Linux
FedoraXen
Nov 21, 2024
Oct 6, 2021
N/A· v4
7.6 HIGH· v3
4.6 MEDIUM· v2
PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform ta...Show more
PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulation. If such a device is passed through to a guest, then on guest shutdown the device is not properly deassigned. The IOMMU configuration for these devices which are not properly deassigned ends up pointing to a freed data structure, including the IO Pagetables. Subsequent DMA or interrupts from the device will have unpredictable behaviour, ranging from IOMMU faults to memory corruption.Show less
1Mcafee
1Drive Encryption
Nov 21, 2024
Oct 1, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffe...Show more
Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.Show less
1Zoom
1Meetings
Nov 21, 2024
Sep 27, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCC...Show more
During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.Show less
1Zoom
1Rooms
Nov 21, 2024
Sep 27, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileg...Show more
During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.Show less
1Mcafee
1Agent
Nov 21, 2024
Sep 22, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation...Show more
Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as the system user, through not correctly protecting a temporary directory used in the repair process and not checking the DLL signature.Show less
1Mcafee
1Mcafee Agent
Nov 21, 2024
Sep 22, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the fil...Show more
Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.Show less
1Sap
1Businessobjects Business Intelligence
Nov 21, 2024
Sep 15, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabil...Show more
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.Show less
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Win32k Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Dec 16, 2025
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows Server 2016Windows Server 2019+1 more
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Microsoft Windows Update Client Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Event Tracing Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability