CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,703)
page 125 of 186| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39944 | Hig | 0.46 | 7.1 | 0.01 | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to… | ||
| CVE-2021-31360 | Hig | 0.46 | 7.1 | 0.00 | Oct 19, 2021 | An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending… | ||
| CVE-2021-41334 | Hig | 0.46 | 7.0 | 0.00 | Oct 13, 2021 | Windows Desktop Bridge Elevation of Privilege Vulnerability | ||
| CVE-2021-38634 | Hig | 0.46 | 7.1 | 0.01 | Sep 15, 2021 | Microsoft Windows Update Client Elevation of Privilege Vulnerability | ||
| CVE-2021-40354 | Hig | 0.46 | 7.1 | 0.01 | Sep 14, 2021 | A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the… | ||
| CVE-2021-34487 | Hig | 0.46 | 7.0 | 0.01 | Aug 12, 2021 | Windows Event Tracing Elevation of Privilege Vulnerability | ||
| CVE-2021-33751 | Hig | 0.46 | 7.0 | 0.01 | Jul 14, 2021 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | ||
| CVE-2021-22326 | Hig | 0.46 | 7.1 | 0.00 | Jun 30, 2021 | A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability. | ||
| CVE-2021-28692 | Hig | 0.46 | 7.1 | 0.00 | Jun 30, 2021 | inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used.… | ||
| CVE-2020-1742 | Hig | 0.46 | 7.0 | 0.00 | Jun 7, 2021 | An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.… | ||
| CVE-2021-26863 | Hig | 0.46 | 7.0 | 0.12 | Mar 11, 2021 | Windows Win32k Elevation of Privilege Vulnerability | ||
| CVE-2021-24095 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2021 | DirectX Elevation of Privilege Vulnerability | ||
| CVE-2021-1729 | Hig | 0.46 | 7.1 | 0.01 | Mar 11, 2021 | Windows Update Stack Setup Elevation of Privilege Vulnerability | ||
| CVE-2021-24087 | Hig | 0.46 | 7.0 | 0.00 | Feb 25, 2021 | Azure IoT CLI extension Elevation of Privilege Vulnerability | ||
| CVE-2020-29031 | Hig | 0.46 | 7.1 | 0.01 | Feb 15, 2021 | An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to… | ||
| CVE-2021-1709 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2021 | Windows Win32k Elevation of Privilege Vulnerability | ||
| CVE-2021-1682 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2021 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2020-26181 | Hig | 0.46 | 7.0 | 0.00 | Jan 5, 2021 | Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges… | ||
| CVE-2020-1488 | Hig | 0.46 | 7.0 | 0.01 | Aug 17, 2020 | An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to… | ||
| CVE-2020-13522 | Hig | 0.46 | 7.1 | 0.00 | Aug 4, 2020 | An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An attacker can send a malicious IRP to trigger this… |
- risk 0.46cvss 7.1epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to…
- risk 0.46cvss 7.1epss 0.00
An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending…
- risk 0.46cvss 7.0epss 0.00
Windows Desktop Bridge Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Windows Update Client Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the…
- risk 0.46cvss 7.0epss 0.01
Windows Event Tracing Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.
- risk 0.46cvss 7.1epss 0.00
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used.…
- risk 0.46cvss 7.0epss 0.00
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.…
- risk 0.46cvss 7.0epss 0.12
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
DirectX Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Windows Update Stack Setup Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Azure IoT CLI extension Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to…
- risk 0.46cvss 7.0epss 0.01
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to…
- risk 0.46cvss 7.1epss 0.00
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An attacker can send a malicious IRP to trigger this…