VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 105 of 164
  • CVE-2024-32899HigJun 13, 2024
    risk 0.46cvss 7.0epss 0.00

    In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-5907HigJun 12, 2024
    risk 0.46cvss 7.0epss 0.00

    A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this…

  • CVE-2024-3137HigApr 2, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Privilege Management in uvdesk/community-skeleton

  • CVE-2024-2228HigMar 22, 2024
    risk 0.46cvss 7.1epss 0.00

    This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.

  • CVE-2024-22795HigFeb 8, 2024
    risk 0.46cvss 7.0epss 0.00

    Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.

  • CVE-2023-51435HigDec 29, 2023
    risk 0.46cvss 7.1epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

  • CVE-2021-37942HigNov 22, 2023
    risk 0.46cvss 7.0epss 0.00

    A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions…

  • CVE-2023-47629HigNov 14, 2023
    risk 0.46cvss 7.1epss 0.00

    DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create an admin account given certain…

  • CVE-2023-36024HigNov 10, 2023
    risk 0.46cvss 7.1epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-5622HigOct 26, 2023
    risk 0.46cvss 7.1epss 0.00

    Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.

  • CVE-2023-36721HigOct 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Error Reporting Service Elevation of Privilege Vulnerability

  • CVE-2023-26062HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that…

  • CVE-2020-23362HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.01

    Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.

  • CVE-2023-21896HigApr 18, 2023
    risk 0.46cvss 7.0epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to…

  • CVE-2023-28758HigMar 23, 2023
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.

  • CVE-2023-21542HigJan 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2023-21531HigJan 10, 2023
    risk 0.46cvss 7.0epss 0.01

    Azure Service Fabric Container Elevation of Privilege Vulnerability

  • CVE-2022-4294HigJan 10, 2023
    risk 0.46cvss 7.1epss 0.00

    Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2022-4687HigDec 23, 2022
    risk 0.46cvss 8.1epss 0.01

    Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2022-42855HigDec 15, 2022
    risk 0.46cvss 7.1epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.