CWE-269
3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,315)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications. |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows AppX Deployment Service Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Storage Spaces Controller Elevation of Privilege Vulnerability |
1Microsoft 4Windows 10 Windows 11Windows Server 2016+1 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Microsoft DWM Core Library Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Kernel Elevation of Privilege Vulnerability |
1Microsoft 4Windows 10 Windows 11Windows Server 2016+1 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Desktop Bridge Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Storage Spaces Controller Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Storage Spaces Controller Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Storage Spaces Controller Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Event Tracing Elevation of Privilege Vulnerability |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 DirectX Graphics Kernel Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Common Log File System Driver Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Common Log File System Driver Elevation of Privilege Vulnerability |
1Microsoft 6Windows 10 Windows 11Windows Server+3 moreJun 17, 2026 Oct 13, 2021 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Windows Nearby Sharing Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Common Log File System Driver Elevation of Privilege Vulnerability |
1Microsoft 9Windows 10 Windows 11Windows 8.1+6 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Storage Spaces Controller Elevation of Privilege Vulnerability |
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external'...Show more |
1Johnsoncontrols 1Exacqvision Web Service Jun 17, 2026 Oct 11, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server. |
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than inte...Show more |