VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 108 of 405
  • CVE-2025-59517HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-61229HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

  • CVE-2025-37155HigNov 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only privileges to gain administrator access…

  • CVE-2025-60705HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.02

    Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59512HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-43476HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to break out of its sandbox.

  • CVE-2025-43407HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. An app may be able to break out of its sandbox.

  • CVE-2025-61156HigOct 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL.

  • CVE-2025-59494HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59201HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59199HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.04

    Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58724HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58714HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55694HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-43340HigSep 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.

  • CVE-2025-43204HigSep 15, 2025
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.

  • CVE-2025-10491HigSep 15, 2025
    risk 0.51cvss 7.8epss 0.00

    The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version…

  • CVE-2025-54098HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49692HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53729HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.