VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 132 of 164
  • CVE-2021-42277MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability

  • CVE-2021-22263MedOct 11, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project…

  • CVE-2021-31836MedSep 22, 2021
    risk 0.36cvss 5.6epss 0.00

    Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

  • CVE-2021-1836MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, tvOS 14.5. A local user may be able to create or modify privileged files.

  • CVE-2021-0256MedApr 22, 2021
    risk 0.36cvss 5.5epss 0.00

    A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow a locally authenticated user with shell access the ability to read portions of sensitive files, such as the master.passwd file. Since mosquitto is shipped with…

  • CVE-2021-0255MedApr 22, 2021
    risk 0.36cvss 5.5epss 0.00

    A local privilege escalation vulnerability in ethtraceroute of Juniper Networks Junos OS may allow a locally authenticated user with shell access to escalate privileges and write to the local filesystem as root. ethtraceroute is shipped with setuid permissions enabled and is…

  • CVE-2021-1258MedJan 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient…

  • CVE-2018-11008MedJan 11, 2021
    risk 0.36cvss 5.5epss 0.01

    An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

  • CVE-2018-11006MedJan 11, 2021
    risk 0.36cvss 5.5epss 0.01

    An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

  • CVE-2020-13517MedDec 18, 2020
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this…

  • CVE-2020-0404MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-15368MedJun 29, 2020
    risk 0.36cvss 5.5epss 0.01

    AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.

  • CVE-2020-3812MedMay 26, 2020
    risk 0.36cvss 5.5epss 0.00

    qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's…

  • CVE-2020-0935MedApr 15, 2020
    risk 0.36cvss 5.5epss 0.01

    An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'.

  • CVE-2019-1454MedJan 24, 2020
    risk 0.36cvss 5.5epss 0.01

    An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.

  • CVE-2019-19151MedDec 23, 2019
    risk 0.36cvss 5.5epss 0.00

    On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions 7.0.0, 6.0.0-6.1.0, and 5.0.0-5.4.0, iWorkflow version 2.3.0, and Enterprise Manager version 3.1.1, authenticated users granted TMOS Shell (tmsh) privileges…

  • CVE-2019-6668MedNov 27, 2019
    risk 0.36cvss 5.5epss 0.00

    The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5 may allow unprivileged users to access files owned by root.

  • CVE-2019-14590MedNov 14, 2019
    risk 0.36cvss 5.5epss 0.00

    Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-11551MedAug 21, 2019
    risk 0.36cvss 5.5epss 0.00

    In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write.

  • CVE-2019-6601MedMar 13, 2019
    risk 0.36cvss 5.5epss 0.00

    In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and PDFs fails to drop group permissions when executing helper scripts.