CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 105 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-32899 | Hig | 0.46 | 7.0 | 0.00 | Jun 13, 2024 | In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2024-5907 | Hig | 0.46 | 7.0 | 0.00 | Jun 12, 2024 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this… | ||
| CVE-2024-3137 | — | Hig | 0.46 | 7.1 | 0.00 | Apr 2, 2024 | Improper Privilege Management in uvdesk/community-skeleton | |
| CVE-2024-2228 | Hig | 0.46 | 7.1 | 0.00 | Mar 22, 2024 | This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population. | ||
| CVE-2024-22795 | Hig | 0.46 | 7.0 | 0.00 | Feb 8, 2024 | Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component. | ||
| CVE-2023-51435 | Hig | 0.46 | 7.1 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | ||
| CVE-2021-37942 | Hig | 0.46 | 7.0 | 0.00 | Nov 22, 2023 | A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions… | ||
| CVE-2023-47629 | Hig | 0.46 | 7.1 | 0.00 | Nov 14, 2023 | DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create an admin account given certain… | ||
| CVE-2023-36024 | Hig | 0.46 | 7.1 | 0.01 | Nov 10, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2023-5622 | Hig | 0.46 | 7.1 | 0.00 | Oct 26, 2023 | Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file. | ||
| CVE-2023-36721 | Hig | 0.46 | 7.0 | 0.00 | Oct 10, 2023 | Windows Error Reporting Service Elevation of Privilege Vulnerability | ||
| CVE-2023-26062 | Hig | 0.46 | 7.0 | 0.00 | Jun 14, 2023 | A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that… | ||
| CVE-2020-23362 | Hig | 0.46 | 7.1 | 0.01 | May 9, 2023 | Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter. | ||
| CVE-2023-21896 | Hig | 0.46 | 7.0 | 0.00 | Apr 18, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to… | ||
| CVE-2023-28758 | Hig | 0.46 | 7.1 | 0.00 | Mar 23, 2023 | An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files. | ||
| CVE-2023-21542 | Hig | 0.46 | 7.0 | 0.00 | Jan 10, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2023-21531 | Hig | 0.46 | 7.0 | 0.01 | Jan 10, 2023 | Azure Service Fabric Container Elevation of Privilege Vulnerability | ||
| CVE-2022-4294 | Hig | 0.46 | 7.1 | 0.00 | Jan 10, 2023 | Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an… | ||
| CVE-2022-4687 | Hig | 0.46 | 8.1 | 0.01 | Dec 23, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2022-42855 | Hig | 0.46 | 7.1 | 0.01 | Dec 15, 2022 | A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements. |
- risk 0.46cvss 7.0epss 0.00
In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for…
- risk 0.46cvss 7.0epss 0.00
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this…
- risk 0.46cvss 7.1epss 0.00
Improper Privilege Management in uvdesk/community-skeleton
- risk 0.46cvss 7.1epss 0.00
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
- risk 0.46cvss 7.0epss 0.00
Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.
- risk 0.46cvss 7.1epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- risk 0.46cvss 7.0epss 0.00
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions…
- risk 0.46cvss 7.1epss 0.00
DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create an admin account given certain…
- risk 0.46cvss 7.1epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.
- risk 0.46cvss 7.0epss 0.00
Windows Error Reporting Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that…
- risk 0.46cvss 7.1epss 0.01
Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.
- risk 0.46cvss 7.0epss 0.00
Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to…
- risk 0.46cvss 7.1epss 0.00
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
- risk 0.46cvss 7.0epss 0.00
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Azure Service Fabric Container Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…
- risk 0.46cvss 8.1epss 0.01
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.46cvss 7.1epss 0.01
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.