VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,726)

page 124 of 187
  • CVE-2025-49156HigJun 17, 2025
    risk 0.46cvss 7.0epss 0.00

    A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2025-27468HigMay 13, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2025-4085HigApr 29, 2025
    risk 0.46cvss 7.1epss 0.00

    An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

  • CVE-2024-2297HigFeb 27, 2025
    risk 0.46cvss 7.1epss 0.00

    The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it possible for authenticated attackers, with…

  • CVE-2025-0651HigJan 22, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option…

  • CVE-2020-9222HigDec 27, 2024
    risk 0.46cvss 7.0epss 0.00

    There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This…

  • CVE-2024-11721HigDec 14, 2024
    risk 0.46cvss 8.1epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in a form. This makes it possible for…

  • CVE-2024-10203HigNov 7, 2024
    risk 0.46cvss 7.0epss 0.00

    Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.

  • CVE-2024-3656HigOct 9, 2024
    risk 0.46cvss 8.1epss 0.03

    A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.

  • CVE-2023-22576HigAug 21, 2024
    risk 0.46cvss 7.0epss 0.00

    Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with…

  • CVE-2024-22069HigAug 8, 2024
    risk 0.46cvss 7.1epss 0.00

    There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

  • CVE-2024-42050HigJul 28, 2024
    risk 0.46cvss 7.0epss 0.00

    The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg.

  • CVE-2024-34725HigJul 9, 2024
    risk 0.46cvss 7.0epss 0.00

    In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32899HigJun 13, 2024
    risk 0.46cvss 7.0epss 0.00

    In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-5907HigJun 12, 2024
    risk 0.46cvss 7.0epss 0.00

    A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this…

  • CVE-2024-3137HigApr 2, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Privilege Management in uvdesk/community-skeleton

  • CVE-2024-2228HigMar 22, 2024
    risk 0.46cvss 7.1epss 0.00

    This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.

  • CVE-2024-22795HigFeb 8, 2024
    risk 0.46cvss 7.0epss 0.00

    Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.

  • CVE-2023-51435HigDec 29, 2023
    risk 0.46cvss 7.1epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

  • CVE-2021-37942HigNov 22, 2023
    risk 0.46cvss 7.0epss 0.00

    A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions…