← Back
CWE-269

3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
1Vmware
1Vrealize Operations
Jun 17, 2026
Aug 10, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.
1Google
1Android
Jun 17, 2026
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional exec...Show more
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-231161832Show less
1Google
1Android
Jun 17, 2026
Aug 10, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interact...Show more
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228314987Show less
1Google
1Android
Jun 17, 2026
Aug 10, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improper input validation. This could lead to local escalation of privilege w...Show more
In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-215003903Show less
1Google
1Android
Jun 17, 2026
Aug 10, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution p...Show more
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228450811Show less
1Google
1Android
Jun 17, 2026
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable...Show more
remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions: Android SoCAndroid ID: A-233972091Show less
1Microsoft
1Azure Site Recovery Vmware To Azure
Jun 17, 2026
Aug 9, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Azure Site Recovery Elevation of Privilege Vulnerability
1Microsoft
1Azure Site Recovery Vmware To Azure
Jun 17, 2026
Aug 9, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Azure Site Recovery Elevation of Privilege Vulnerability
1Microsoft
1Azure Site Recovery Vmware To Azure
Jun 17, 2026
Aug 9, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Azure Site Recovery Elevation of Privilege Vulnerability
1Microsoft
1Azure Site Recovery Vmware To Azure
Jun 17, 2026
Aug 9, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Azure Site Recovery Elevation of Privilege Vulnerability
1Microsoft
1Azure Site Recovery Vmware To Azure
Jun 17, 2026
Aug 9, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Azure Site Recovery Elevation of Privilege Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Defender Credential Guard Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Storage Spaces Direct Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Storage Spaces Direct Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Storage Spaces Direct Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Storage Spaces Direct Elevation of Privilege Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability