CWE-273
45 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Check for Dropped Privileges
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
CVEs (45)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 5Visual Studio Visual Studio 2017Windows 10+2 moreJun 17, 2026 Dec 12, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka "Diagnostics Hub Standard Collector Service Elevation of Privilege V...Show more |
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens. |
2Alienvault Nfsen3Nfsen OssimUnified Security ManagementMay 13, 2026 Mar 22, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-201...Show more |
3Fedoraproject Libuv ProjectNodejs3Fedora LibuvNode.jsMay 6, 2026 May 18, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors. |
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, whi...Show more |