VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 153 of 186
  • CVE-2021-1258MedJan 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient…

  • CVE-2018-11008MedJan 11, 2021
    risk 0.36cvss 5.5epss 0.01

    An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

  • CVE-2018-11006MedJan 11, 2021
    risk 0.36cvss 5.5epss 0.01

    An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

  • CVE-2020-13517MedDec 18, 2020
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this…

  • CVE-2020-0404MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-15368MedJun 29, 2020
    risk 0.36cvss 5.5epss 0.01

    AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.

  • CVE-2020-3812MedMay 26, 2020
    risk 0.36cvss 5.5epss 0.00

    qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's…

  • CVE-2020-0935MedApr 15, 2020
    risk 0.36cvss 5.5epss 0.01

    An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'.

  • CVE-2019-1454MedJan 24, 2020
    risk 0.36cvss 5.5epss 0.01

    An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.

  • CVE-2019-19151MedDec 23, 2019
    risk 0.36cvss 5.5epss 0.00

    On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions 7.0.0, 6.0.0-6.1.0, and 5.0.0-5.4.0, iWorkflow version 2.3.0, and Enterprise Manager version 3.1.1, authenticated users granted TMOS Shell (tmsh) privileges…

  • CVE-2019-6668MedNov 27, 2019
    risk 0.36cvss 5.5epss 0.00

    The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5 may allow unprivileged users to access files owned by root.

  • CVE-2019-14590MedNov 14, 2019
    risk 0.36cvss 5.5epss 0.00

    Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-11551MedAug 21, 2019
    risk 0.36cvss 5.5epss 0.00

    In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write.

  • CVE-2019-6601MedMar 13, 2019
    risk 0.36cvss 5.5epss 0.00

    In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and PDFs fails to drop group permissions when executing helper scripts.

  • CVE-2015-9267MedOct 1, 2018
    risk 0.36cvss 5.5epss 0.00

    Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.

  • CVE-2018-9334MedJul 3, 2018
    risk 0.36cvss 5.5epss 0.00

    The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allow an attacker to access the GlobalProtect password hashes of local users via manipulation of the HTML markup.

  • CVE-2017-7767MedJun 11, 2018
    risk 0.36cvss 5.5epss 0.00

    The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects…

  • CVE-2017-5409MedJun 11, 2018
    risk 0.36cvss 5.5epss 0.00

    The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only…

  • CVE-2018-4173MedApr 13, 2018
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app.

  • CVE-2017-11747MedJul 30, 2017
    risk 0.36cvss 5.5epss 0.00

    main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tinyproxy.pid modification before a root…