CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 106 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31166 | Hig | 0.46 | 8.1 | 0.01 | Sep 7, 2022 | XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation. More specifically, editing a right with… | ||
| CVE-2022-30298 | Hig | 0.46 | 7.0 | 0.00 | Sep 6, 2022 | An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root. | ||
| CVE-2022-33646 | Hig | 0.46 | 7.0 | 0.00 | Aug 9, 2022 | Azure Batch Node Agent Elevation of Privilege Vulnerability | ||
| CVE-2022-21827 | Hig | 0.46 | 7.1 | 0.00 | May 26, 2022 | An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as… | ||
| CVE-2022-21699 | Hig | 0.46 | 8.2 | 0.01 | Jan 19, 2022 | IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing… | ||
| CVE-2021-31833 | Hig | 0.46 | 7.1 | 0.00 | Jan 4, 2022 | Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would… | ||
| CVE-2021-39944 | Hig | 0.46 | 7.1 | 0.01 | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to… | ||
| CVE-2021-31360 | Hig | 0.46 | 7.1 | 0.00 | Oct 19, 2021 | An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending… | ||
| CVE-2021-41334 | Hig | 0.46 | 7.0 | 0.00 | Oct 13, 2021 | Windows Desktop Bridge Elevation of Privilege Vulnerability | ||
| CVE-2021-38634 | Hig | 0.46 | 7.1 | 0.01 | Sep 15, 2021 | Microsoft Windows Update Client Elevation of Privilege Vulnerability | ||
| CVE-2021-40354 | Hig | 0.46 | 7.1 | 0.01 | Sep 14, 2021 | A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the… | ||
| CVE-2021-34487 | Hig | 0.46 | 7.0 | 0.01 | Aug 12, 2021 | Windows Event Tracing Elevation of Privilege Vulnerability | ||
| CVE-2021-33751 | Hig | 0.46 | 7.0 | 0.01 | Jul 14, 2021 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | ||
| CVE-2021-22326 | Hig | 0.46 | 7.1 | 0.00 | Jun 30, 2021 | A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability. | ||
| CVE-2021-28692 | Hig | 0.46 | 7.1 | 0.00 | Jun 30, 2021 | inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used.… | ||
| CVE-2020-1742 | Hig | 0.46 | 7.0 | 0.00 | Jun 7, 2021 | An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.… | ||
| CVE-2021-26863 | Hig | 0.46 | 7.0 | 0.12 | Mar 11, 2021 | Windows Win32k Elevation of Privilege Vulnerability | ||
| CVE-2021-24095 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2021 | DirectX Elevation of Privilege Vulnerability | ||
| CVE-2021-1729 | Hig | 0.46 | 7.1 | 0.01 | Mar 11, 2021 | Windows Update Stack Setup Elevation of Privilege Vulnerability | ||
| CVE-2021-24087 | Hig | 0.46 | 7.0 | 0.00 | Feb 25, 2021 | Azure IoT CLI extension Elevation of Privilege Vulnerability |
- risk 0.46cvss 8.1epss 0.01
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation. More specifically, editing a right with…
- risk 0.46cvss 7.0epss 0.00
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
- risk 0.46cvss 7.0epss 0.00
Azure Batch Node Agent Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as…
- risk 0.46cvss 8.2epss 0.01
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing…
- risk 0.46cvss 7.1epss 0.00
Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would…
- risk 0.46cvss 7.1epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to…
- risk 0.46cvss 7.1epss 0.00
An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending…
- risk 0.46cvss 7.0epss 0.00
Windows Desktop Bridge Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Windows Update Client Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the…
- risk 0.46cvss 7.0epss 0.01
Windows Event Tracing Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.
- risk 0.46cvss 7.1epss 0.00
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used.…
- risk 0.46cvss 7.0epss 0.00
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.…
- risk 0.46cvss 7.0epss 0.12
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
DirectX Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Windows Update Stack Setup Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Azure IoT CLI extension Elevation of Privilege Vulnerability