VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 110 of 164
  • CVE-2024-4395HigJun 27, 2024
    risk 0.44cvss 7.8epss 0.00

    The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.

  • CVE-2024-36499MedJun 14, 2024
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2022-37019MedJun 10, 2024
    risk 0.44cvss 6.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

  • CVE-2024-37364MedJun 6, 2024
    risk 0.44cvss 6.8epss 0.00

    Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive information (such as hotel invoice content with PII), and potentially create unauthorized room keys, by entering a guest-search quote…

  • CVE-2024-29975MedJun 4, 2024
    risk 0.44cvss 6.7epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with…

  • CVE-2023-48319MedMay 17, 2024
    risk 0.44cvss 6.8epss 0.01

    Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.

  • CVE-2023-45320MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-40155MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-31556HigMay 14, 2024
    risk 0.44cvss 7.8epss 0.00

    An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.

  • CVE-2024-31953MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user…

  • CVE-2024-20021MedMay 6, 2024
    risk 0.44cvss 6.7epss 0.00

    In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID:…

  • CVE-2024-25987MedMar 11, 2024
    risk 0.44cvss 6.7epss 0.00

    In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-22235MedFeb 21, 2024
    risk 0.44cvss 6.7epss 0.00

    VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

  • CVE-2024-23764MedFeb 8, 2024
    risk 0.44cvss 6.7epss 0.00

    Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoint Protection 17 and later.

  • CVE-2023-41776MedJan 3, 2024
    risk 0.44cvss 6.7epss 0.00

    There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

  • CVE-2023-48406MedDec 8, 2023
    risk 0.44cvss 6.7epss 0.00

    there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-44292MedNov 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.

  • CVE-2023-44282MedNov 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.

  • CVE-2022-41700MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-5847MedNov 1, 2023
    risk 0.44cvss 6.7epss 0.00

    Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Linux hosts.