CWE-269
3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,315)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreAug 19, 2026 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NTFS Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreAug 19, 2026 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NTFS Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreAug 19, 2026 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
1Microsoft 4Windows 10 Windows Server 2016Windows Server 2019+1 moreAug 19, 2026 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Desktop Bridge Elevation of Privilege Vulnerability |
1Hp 5Color Laserjet Pro Mfp M277 B3q10a Firmware Color Laserjet Pro Mfp M277 B3q10v FirmwareColor Laserjet Pro Mfp M277 B3q11a Firmware+2 moreJun 17, 2026 Nov 9, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A potential security vulnerability has been identified for HP LaserJet Solution Software (for certain HP LaserJet Printers) which may lead to unauthorized elevation of privilege on the client. |
Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation. |
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge. |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 Nov 4, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerabil...Show more |
A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts |
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to execute privileged operations by the guest OS, which may lead to information disclosure, data tamper...Show more |
1Bitdefender 2Endpoint Security Tools Total SecurityJun 17, 2026 Oct 28, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT AUTHORITY\System. Impersonation enables the server thread to perform ac...Show more |
Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file...Show more |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesJun 17, 2026 Oct 21, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installati...Show more |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesJun 17, 2026 Oct 21, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on...Show more |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesJun 17, 2026 Oct 21, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on...Show more |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesJun 17, 2026 Oct 21, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on...Show more |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesJun 17, 2026 Oct 21, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on...Show more |
1Juniper 2Junos Junos Os EvolvedJun 17, 2026 Oct 19, 2021 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a sys...Show more |
A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to cause the Juniper DHCP daemon (jdhcpd) process to crash, resulting in a Denial of Servic...Show more |
An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticate...Show more |