VYPR

CWE-270

Privilege Context Switching Error

BaseDraft

Description

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-17 · CAPEC-30 · CAPEC-35

CVEs mapped to this weakness (26)

page 1 of 2
  • CVE-2023-26475CriMar 2, 2023
    risk 0.62cvss 9.9epss 0.64

    XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been…

  • CVE-2024-11263CriNov 15, 2024
    risk 0.60cvss 9.3epss 0.00

    When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols.

  • CVE-2023-37912CriOct 25, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and `org.xwiki.platform:xwiki-rendering-macro-footnotes` and prior to version…

  • CVE-2023-25754CriMay 8, 2023
    risk 0.57cvss 9.8epss 0.02

    Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.

  • CVE-2019-14819HigJan 7, 2020
    risk 0.57cvss 8.8epss 0.01

    A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges…

  • CVE-2025-9408HigNov 11, 2025
    risk 0.53cvss 8.1epss 0.00

    System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege escalation for malicious userspace processes.

  • CVE-2024-36513HigNov 12, 2024
    risk 0.53cvss 8.2epss 0.00

    A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.

  • CVE-2026-9560HigMay 26, 2026
    risk 0.51cvss 7.8epss 0.01

    Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

  • CVE-2025-60721HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

  • CVE-2024-46975HigFeb 22, 2025
    risk 0.51cvss 7.9epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.

  • CVE-2026-34853HigApr 13, 2026
    risk 0.50cvss 7.7epss 0.00

    Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-49581HigJun 13, 2025
    risk 0.50cvss 8.8epss 0.01

    XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki installation. The main problem is that if a…

  • CVE-2024-12570MedDec 12, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging…

  • CVE-2020-7019MedAug 18, 2020
    risk 0.42cvss 6.5epss 0.01

    In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could…

  • CVE-2025-26499MedSep 11, 2025
    risk 0.39cvss 6.0epss 0.00

    Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This flaw allows one user to be granted a token intended for another user, resulting in impersonation until the session is ended. This flaw cannot be intentionally…

  • CVE-2024-8641MedSep 12, 2024
    risk 0.37cvss 6.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to…

  • CVE-2025-46406MedJul 10, 2025
    risk 0.36cvss 5.6epss 0.00

    A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform limited privileged activities across the Division boundary. This issue affects Command Centre Server: 9.30 prior to…

  • CVE-2020-1719MedJun 7, 2021
    risk 0.35cvss 5.4epss 0.01

    A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.

  • CVE-2024-47173MedOct 24, 2024
    risk 0.29cvss 5.5epss 0.00

    Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue.

  • CVE-2024-37294MedJun 11, 2024
    risk 0.29cvss 5.5epss 0.00

    Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users should upgrade to versions 2022.10.17, 2023.10.17, or 2024.04 of the…