VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 130 of 186
  • CVE-2022-34754MedJul 13, 2022
    risk 0.44cvss 6.8epss 0.00

    A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: Acti9 PowerTag Link C (A9XELC10-A) (V1.7.5 and prior), Acti9 PowerTag Link C (A9XELC10-B) (V2.12.0 and prior)

  • CVE-2022-26057MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a…

  • CVE-2022-31594MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.

  • CVE-2021-27767MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2021-27766MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2021-27765MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2022-1108MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-1107MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.00

    During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

  • CVE-2020-16238MedApr 14, 2022
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with command line access to the underlying Linux system to escalate privileges to the…

  • CVE-2018-4478MedDec 23, 2021
    risk 0.44cvss 6.8epss 0.00

    A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan. An attacker with physical access to a device may be able to elevate privileges.

  • CVE-2021-36316MedDec 21, 2021
    risk 0.44cvss 6.7epss 0.01

    Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability in AUI. A malicious user with high privileges could potentially exploit this vulnerability, leading to the disclosure of the AUI info and performing some…

  • CVE-2021-40124MedNov 4, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts…

  • CVE-2021-23877MedOct 26, 2021
    risk 0.44cvss 6.7epss 0.00

    Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.

  • CVE-2021-0691MedOct 6, 2021
    risk 0.44cvss 6.7epss 0.00

    In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution privileges needed. User…

  • CVE-2021-34493MedJul 14, 2021
    risk 0.44cvss 6.7epss 0.01

    Windows Partition Management Driver Elevation of Privilege Vulnerability

  • CVE-2021-22118HigMay 27, 2021
    risk 0.44cvss 7.8epss 0.00

    In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been…

  • CVE-2021-1447MedMay 6, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root. This vulnerability is due to a procedural flaw in the password…

  • CVE-2021-29449MedApr 14, 2021
    risk 0.44cvss 6.3epss 0.02

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

  • CVE-2021-28458HigApr 13, 2021
    risk 0.44cvss 7.8epss 0.02

    Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability

  • CVE-2021-25363MedApr 9, 2021
    risk 0.44cvss 6.8epss 0.00

    An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.