CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 131 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-5909 | Med | 0.36 | 5.5 | 0.00 | Jun 12, 2024 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | ||
| CVE-2024-2431 | Med | 0.36 | 5.5 | 0.00 | Mar 13, 2024 | An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode. | ||
| CVE-2022-32931 | Med | 0.36 | 5.5 | 0.00 | Jan 10, 2024 | This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access private information. | ||
| CVE-2023-5960 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2023 | An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device. | ||
| CVE-2023-5797 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2023 | An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware… | ||
| CVE-2023-5650 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2023 | An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16… | ||
| CVE-2023-37925 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2023 | An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware… | ||
| CVE-2023-35140 | Med | 0.36 | 5.5 | 0.00 | Nov 7, 2023 | The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device. | ||
| CVE-2023-21376 | Med | 0.36 | 5.5 | 0.00 | Oct 30, 2023 | In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-4936 | Med | 0.36 | 5.5 | 0.00 | Oct 11, 2023 | It is possible to sideload a compromised DLL during the installation at elevated privilege. | ||
| CVE-2023-35671 | Med | 0.36 | 5.5 | 0.00 | Sep 11, 2023 | In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information… | ||
| CVE-2023-4140 | Med | 0.36 | 6.6 | 0.01 | Aug 4, 2023 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such… | ||
| CVE-2023-29819 | Med | 0.36 | 5.5 | 0.00 | May 12, 2023 | An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload. | ||
| CVE-2023-1548 | Med | 0.36 | 5.5 | 0.00 | Apr 18, 2023 | A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above) | ||
| CVE-2022-3421 | Med | 0.36 | 5.6 | 0.00 | Oct 17, 2022 | An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a binary in that directory with execute… | ||
| CVE-2017-20028 | Med | 0.36 | 5.6 | 0.01 | Jun 9, 2022 | A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is able to address this issue. It… | ||
| CVE-2022-20112 | Med | 0.36 | 5.5 | 0.00 | May 10, 2022 | In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction… | ||
| CVE-2022-20051 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2022 | In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219127; Issue… | ||
| CVE-2021-43211 | Med | 0.36 | 5.5 | 0.01 | Nov 24, 2021 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | ||
| CVE-2021-42280 | Med | 0.36 | 5.5 | 0.01 | Nov 10, 2021 | Windows Feedback Hub Elevation of Privilege Vulnerability |
- risk 0.36cvss 5.5epss 0.00
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
- risk 0.36cvss 5.5epss 0.00
An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.
- risk 0.36cvss 5.5epss 0.00
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access private information.
- risk 0.36cvss 5.5epss 0.00
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device.
- risk 0.36cvss 5.5epss 0.00
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware…
- risk 0.36cvss 5.5epss 0.00
An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16…
- risk 0.36cvss 5.5epss 0.00
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware…
- risk 0.36cvss 5.5epss 0.00
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.
- risk 0.36cvss 5.5epss 0.00
In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
It is possible to sideload a compromised DLL during the installation at elevated privilege.
- risk 0.36cvss 5.5epss 0.00
In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information…
- risk 0.36cvss 6.6epss 0.01
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such…
- risk 0.36cvss 5.5epss 0.00
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.
- risk 0.36cvss 5.5epss 0.00
A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above)
- risk 0.36cvss 5.6epss 0.00
An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a binary in that directory with execute…
- risk 0.36cvss 5.6epss 0.01
A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is able to address this issue. It…
- risk 0.36cvss 5.5epss 0.00
In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- risk 0.36cvss 5.5epss 0.00
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219127; Issue…
- risk 0.36cvss 5.5epss 0.01
Windows 10 Update Assistant Elevation of Privilege Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Feedback Hub Elevation of Privilege Vulnerability