VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,703)

page 125 of 186
  • CVE-2021-39944HigDec 13, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to…

  • CVE-2021-31360HigOct 19, 2021
    risk 0.46cvss 7.1epss 0.00

    An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending…

  • CVE-2021-41334HigOct 13, 2021
    risk 0.46cvss 7.0epss 0.00

    Windows Desktop Bridge Elevation of Privilege Vulnerability

  • CVE-2021-38634HigSep 15, 2021
    risk 0.46cvss 7.1epss 0.01

    Microsoft Windows Update Client Elevation of Privilege Vulnerability

  • CVE-2021-40354HigSep 14, 2021
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the…

  • CVE-2021-34487HigAug 12, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Event Tracing Elevation of Privilege Vulnerability

  • CVE-2021-33751HigJul 14, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Storage Spaces Controller Elevation of Privilege Vulnerability

  • CVE-2021-22326HigJun 30, 2021
    risk 0.46cvss 7.1epss 0.00

    A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.

  • CVE-2021-28692HigJun 30, 2021
    risk 0.46cvss 7.1epss 0.00

    inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used.…

  • CVE-2020-1742HigJun 7, 2021
    risk 0.46cvss 7.0epss 0.00

    An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.…

  • CVE-2021-26863HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.12

    Windows Win32k Elevation of Privilege Vulnerability

  • CVE-2021-24095HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.01

    DirectX Elevation of Privilege Vulnerability

  • CVE-2021-1729HigMar 11, 2021
    risk 0.46cvss 7.1epss 0.01

    Windows Update Stack Setup Elevation of Privilege Vulnerability

  • CVE-2021-24087HigFeb 25, 2021
    risk 0.46cvss 7.0epss 0.00

    Azure IoT CLI extension Elevation of Privilege Vulnerability

  • CVE-2020-29031HigFeb 15, 2021
    risk 0.46cvss 7.1epss 0.01

    An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to…

  • CVE-2021-1709HigJan 12, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Win32k Elevation of Privilege Vulnerability

  • CVE-2021-1682HigJan 12, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2020-26181HigJan 5, 2021
    risk 0.46cvss 7.0epss 0.00

    Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges…

  • CVE-2020-1488HigAug 17, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to…

  • CVE-2020-13522HigAug 4, 2020
    risk 0.46cvss 7.1epss 0.00

    An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An attacker can send a malicious IRP to trigger this…