← Back
CWE-269

2,753 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (2,753)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Code42
1Code42
Nov 21, 2024
Jul 19, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organization can impersonate a user with web restore permission. When requesting the toke...Show more
In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organization can impersonate a user with web restore permission. When requesting the token to do a web restore, an administrator with permission to manage a user could request the token of that user. If the administrator was not authorized to perform web restores but the user was authorized to perform web restores, this would allow the administrator to impersonate the user with greater permissions. In order to exploit this vulnerability, the user would have to be an administrator with access to manage an organization with a user with greater permissions than themselves.Show less
1Llnl
1Model Specific Registers Safe
Nov 21, 2024
Jul 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: A...Show more
Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: An attacker could exploit a bug in ioctl interface whitelist checking, in order to write to model specific registers, normally a function reserved for the root user. The fixed version is: v1.2.0.Show less
1Mikogo
1Mikogo
Nov 21, 2024
Jul 12, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Windows versions of Snapview Mikogo, versions before 5.10.2 are affected by insecure implementations which allow local attackers to escalate privileges.
1Optergy
2Enterprise
Proton
Nov 21, 2024
Jul 1, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.
1Actiontec
1Web6000q Firmware
Nov 21, 2024
Jun 27, 2019
N/A· v4
8.8 HIGH· v3
10.0 HIGH· v2
An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to anything on the 169.254.1.0/24 subnet, and obtain root access by conne...Show more
An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to anything on the 169.254.1.0/24 subnet, and obtain root access by connecting to 169.254.1.2 port 23 with telnet/netcat.Show less
1Dell
2Supportassist For Business Pcs
Supportassist For Home Pcs
Nov 21, 2024
Jun 20, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malic...Show more
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread handle to gain system privileges on the affected machine.Show less
1Ibm
1Cognos Controller
Nov 21, 2024
Jun 17, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882.
1Ibm
1Cognos Controller
Nov 21, 2024
Jun 17, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
May 20, 2025
Jun 12, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a...Show more
An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (e.g. a remote code execution vulnerability and another elevation of privilege) that could take advantage of the elevated privileges when running. The update addresses the vulnerability by correcting how the Windows Audio Service handles processes these requests.Show less
1Misp
1Misp
Nov 21, 2024
Jun 11, 2019
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however...Show more
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however, could be abused in a situation where the host organization of an instance creates organization admins. An organization admin could set a password manually for the site admin or simply use the API key of the site admin to impersonate them. The potential for abuse only occurs when the host organization creates lower-privilege organization admins instead of the usual site admins. Also, only organization admins of the same organization as the site admin could abuse this.Show less
1Enttec
4Datagate Mk2 Firmware
E Streamer Mk2 FirmwarePixelator Firmware+1 more
Nov 21, 2024
Jun 7, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropria...Show more
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore, the user account that controls the web application service is granted full access to run any system commands with elevated privilege, without the need for password authentication. Should vulnerabilities be identified and exploited within the web application, it may be possible for a threat actor to create or run high-privileged binaries or executables that are available within the operating system of the device.)Show less
1Ibm
1Security Information Queue
Nov 21, 2024
Jun 6, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 159227.
1Ibm
10Control Desk
Maximo Asset ManagementMaximo For Aviation+7 more
Nov 21, 2024
Jun 6, 2019
N/A· v4
2.1 LOW· v3
2.1 LOW· v2
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.
1Htc
1Viveport
Nov 21, 2024
Jun 3, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service.
1Redhat
1Rkt
Nov 21, 2024
Jun 3, 2019
N/A· v4
7.7 HIGH· v3
6.9 MEDIUM· v2
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the application...Show more
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.Show less
1Bosch
1Smart Home Controller Firmware
Nov 21, 2024
May 29, 2019
N/A· v4
7.1 HIGH· v3
6.8 MEDIUM· v2
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permiss...Show more
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.Show less
1Bosch
1Smart Home Controller Firmware
Nov 21, 2024
May 29, 2019
N/A· v4
8.0 HIGH· v3
4.9 MEDIUM· v2
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissio...Show more
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.Show less
1Bosch
1Smart Home Controller Firmware
Nov 21, 2024
May 29, 2019
N/A· v4
8.0 HIGH· v3
5.4 MEDIUM· v2
A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In...Show more
A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack.Show less
1Ca
2Risk Authentication
Strong Authentication
Nov 21, 2024
May 28, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows...Show more
A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in some cases where an account has customized and limited privileges.Show less
1Microsoft
1Azure Active Directory Connect
Nov 21, 2024
May 16, 2019
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privil...Show more
An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacker would need to authenticate to the Azure AD Connect server, aka 'Microsoft Azure AD Connect Elevation of Privilege Vulnerability'.Show less