← Back
CWE-269

2,777 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (2,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Aug 12, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Microsoft Windows Defender Elevation of Privilege Vulnerability
1Netskope
1Netskope
Nov 21, 2024
Aug 12, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.
1Contao
1Contao
Nov 21, 2024
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they h...Show more
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form generator or disable the login for untrusted back end users.Show less
1Dell
1Powerscale Onefs
Feb 20, 2026
Aug 10, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege.
1Set User Project
1Set User
Nov 21, 2024
Aug 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user().
1Cisco
2Confd
Network Services Orchestrator
Nov 21, 2024
Aug 4, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root. To exploit this vulnerability, an atta...Show more
A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root. To exploit this vulnerability, an attacker must have a valid account on an affected device. The vulnerability exists because the affected software incorrectly runs the SFTP user service at the privilege level of the account that was running when the ConfD built-in Secure Shell (SSH) server for CLI was enabled. If the ConfD built-in SSH server was not enabled, the device is not affected by this vulnerability. An attacker with low-level privileges could exploit this vulnerability by authenticating to an affected device and issuing a series of commands at the SFTP interface. A successful exploit could allow the attacker to elevate privileges to the level of the account under which ConfD is running, which is commonly root. Note: Any user who can authenticate to the built-in SSH server may exploit this vulnerability. By default, all ConfD users have this access if the server is enabled. Software updates that address this vulnerability have been released.Show less
1Huawei
1Harmonyos
Nov 21, 2024
Aug 3, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.
1Comelitgroup
1Away From Home
Nov 21, 2024
Aug 3, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. For example, an attacker can achieve hi...Show more
An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. For example, an attacker can achieve high privileges (installer or administrator) for the graphical interface via a 1C000000000S value for domus, in conjunction with a zero value for logged.Show less
1Huawei
2Ecns280 Td Firmware
Ese620x Vess Firmware
Nov 21, 2024
Aug 2, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful expl...Show more
There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful exploit will cause privilege escalation.Affected product versions include:eCNS280_TD V100R005C00,V100R005C10;eSE620X vESS V100R001C10SPC200,V100R001C20SPC200.Show less
1Swisslog Healthcare
1Hmi 3 Control Panel Firmware
Nov 21, 2024
Aug 2, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credential...Show more
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of the device.Show less
1Mbconnectline
1Mbdialup
Nov 21, 2024
Aug 2, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in a...Show more
In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.Show less
1Neo4j
1Graph Databse
Nov 21, 2024
Jul 30, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges.
1Techsmith
1Snagit
Jun 10, 2026
Jul 26, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security v...Show more
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. See reference document for more details.Show less
1Techsmith
1Snagit
Jun 10, 2026
Jul 26, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to ignore other safety...Show more
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to ignore other safety mechanisms provided by the Host OS. See reference document for more details.Show less
1Asrock
1Box R1000 Firmware
Nov 21, 2024
Jul 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.
1Akkadianlabs
2Ova Appliance
Provisioning Manager
Nov 21, 2024
Jul 22, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped...Show more
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Feb 24, 2026
Jul 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code wi...Show more
<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p><strong>UPDATE</strong> August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see <a href="https://support.microsoft.com/help/5005652">KB5005652</a>.</p>Show less
1Microsoft
2Windows 10
Windows Server 2016
Nov 21, 2024
Jul 16, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
1Microsoft
6Windows 10
Windows 8.1Windows Rt 8.1+3 more
Nov 21, 2024
Jul 16, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Storage Spaces Controller Elevation of Privilege Vulnerability
1Microsoft
6Windows 10
Windows 8.1Windows Rt 8.1+3 more
Nov 21, 2024
Jul 16, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows AppContainer Elevation Of Privilege Vulnerability