VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 106 of 164
  • CVE-2022-31166HigSep 7, 2022
    risk 0.46cvss 8.1epss 0.01

    XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation. More specifically, editing a right with…

  • CVE-2022-30298HigSep 6, 2022
    risk 0.46cvss 7.0epss 0.00

    An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.

  • CVE-2022-33646HigAug 9, 2022
    risk 0.46cvss 7.0epss 0.00

    Azure Batch Node Agent Elevation of Privilege Vulnerability

  • CVE-2022-21827HigMay 26, 2022
    risk 0.46cvss 7.1epss 0.00

    An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as…

  • CVE-2022-21699HigJan 19, 2022
    risk 0.46cvss 8.2epss 0.01

    IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing…

  • CVE-2021-31833HigJan 4, 2022
    risk 0.46cvss 7.1epss 0.00

    Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would…

  • CVE-2021-39944HigDec 13, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to…

  • CVE-2021-31360HigOct 19, 2021
    risk 0.46cvss 7.1epss 0.00

    An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending…

  • CVE-2021-41334HigOct 13, 2021
    risk 0.46cvss 7.0epss 0.00

    Windows Desktop Bridge Elevation of Privilege Vulnerability

  • CVE-2021-38634HigSep 15, 2021
    risk 0.46cvss 7.1epss 0.01

    Microsoft Windows Update Client Elevation of Privilege Vulnerability

  • CVE-2021-40354HigSep 14, 2021
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the…

  • CVE-2021-34487HigAug 12, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Event Tracing Elevation of Privilege Vulnerability

  • CVE-2021-33751HigJul 14, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Storage Spaces Controller Elevation of Privilege Vulnerability

  • CVE-2021-22326HigJun 30, 2021
    risk 0.46cvss 7.1epss 0.00

    A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.

  • CVE-2021-28692HigJun 30, 2021
    risk 0.46cvss 7.1epss 0.00

    inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used.…

  • CVE-2020-1742HigJun 7, 2021
    risk 0.46cvss 7.0epss 0.00

    An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.…

  • CVE-2021-26863HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.12

    Windows Win32k Elevation of Privilege Vulnerability

  • CVE-2021-24095HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.01

    DirectX Elevation of Privilege Vulnerability

  • CVE-2021-1729HigMar 11, 2021
    risk 0.46cvss 7.1epss 0.01

    Windows Update Stack Setup Elevation of Privilege Vulnerability

  • CVE-2021-24087HigFeb 25, 2021
    risk 0.46cvss 7.0epss 0.00

    Azure IoT CLI extension Elevation of Privilege Vulnerability