CWE-269
2,777 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,777)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Malware Protection Engine Nov 21, 2024 Aug 12, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Microsoft Windows Defender Elevation of Privilege Vulnerability |
Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM. |
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they h...Show more |
Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege. |
The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user(). |
1Cisco 2Confd Network Services OrchestratorNov 21, 2024 Aug 4, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root. To exploit this vulnerability, an atta...Show more |
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges. |
An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. For example, an attacker can achieve hi...Show more |
1Huawei 2Ecns280 Td Firmware Ese620x Vess FirmwareNov 21, 2024 Aug 2, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful expl...Show more |
1Swisslog Healthcare 1Hmi 3 Control Panel Firmware Nov 21, 2024 Aug 2, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credential...Show more |
In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in a...Show more |
A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges. |
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security v...Show more |
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to ignore other safety...Show more |
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM. |
1Akkadianlabs 2Ova Appliance Provisioning ManagerNov 21, 2024 Jul 22, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreFeb 24, 2026 Jul 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code wi...Show more |
1Microsoft 2Windows 10 Windows Server 2016Nov 21, 2024 Jul 16, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreNov 21, 2024 Jul 16, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Storage Spaces Controller Elevation of Privilege Vulnerability |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreNov 21, 2024 Jul 16, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows AppContainer Elevation Of Privilege Vulnerability |