VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 83 of 164
  • CVE-2011-3349HigNov 19, 2019
    risk 0.51cvss 7.8epss 0.00

    lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.

  • CVE-2011-4954HigNov 19, 2019
    risk 0.51cvss 7.8epss 0.00

    cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE

  • CVE-2018-18368HigNov 15, 2019
    risk 0.51cvss 7.8epss 0.01

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally…

  • CVE-2019-2193HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.00

    In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lead to local escalation of privilege, leaving an Admin app installed with no indication to the user, with User execution privileges…

  • CVE-2019-16519HigOct 14, 2019
    risk 0.51cvss 7.8epss 0.00

    ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in scheduled tasks.

  • CVE-2019-9745HigOct 14, 2019
    risk 0.51cvss 7.8epss 0.00

    CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service (Recognition Update Client Service) via an insecure communication channel (Named Pipe). The data (JSON) sent via this channel is…

  • CVE-2018-9425HigSep 27, 2019
    risk 0.51cvss 7.8epss 0.00

    In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:…

  • CVE-2019-15720HigAug 28, 2019
    risk 0.51cvss 7.8epss 0.00

    CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level access, a user can modify the backup plan and add a Pre backup action script that executes on behalf of NT AUTHORITY\SYSTEM.

  • CVE-2019-4448HigAug 26, 2019
    risk 0.51cvss 7.8epss 0.00

    IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a…

  • CVE-2019-1162HigAug 14, 2019
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then…

  • CVE-2019-12731HigJul 12, 2019
    risk 0.51cvss 7.8epss 0.00

    The Windows versions of Snapview Mikogo, versions before 5.10.2 are affected by insecure implementations which allow local attackers to escalate privileges.

  • CVE-2019-3735HigJun 20, 2019
    risk 0.51cvss 7.8epss 0.00

    Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by…

  • CVE-2019-1007HigJun 12, 2019
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the…

  • CVE-2019-12176HigJun 3, 2019
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service.

  • CVE-2019-10239HigApr 24, 2019
    risk 0.51cvss 7.8epss 0.00

    Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to obtain cleartext credentials of the stored account.

  • CVE-2018-4008HigApr 15, 2019
    risk 0.51cvss 7.8epss 0.00

    An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript command. The command takes a user-supplied script argument and executes it under root context. A user with local access can use this vulnerability to raise their…

  • CVE-2018-18252HigMar 15, 2019
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to unprivileged users via the --system option.

  • CVE-2018-19012HigJan 28, 2019
    risk 0.51cvss 7.8epss 0.00

    Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk…

  • CVE-2018-15331HigDec 20, 2018
    risk 0.51cvss 7.8epss 0.01

    On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system.

  • CVE-2018-11965HigDec 20, 2018
    risk 0.51cvss 7.8epss 0.00

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Anyone can execute proptrigger.sh which will lead to change in properties.