VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 109 of 405
  • CVE-2025-49707HigAug 12, 2025
    risk 0.51cvss 7.9epss 0.00

    Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.

  • CVE-2025-27062HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while handling client exceptions, allowing unauthorized channel access.

  • CVE-2025-50777HigJul 30, 2025
    risk 0.51cvss 7.8epss 0.00

    The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials…

  • CVE-2025-47993HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-23365HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and…

  • CVE-2025-27689HigJun 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-47962HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.02

    Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32714HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2024-53010HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur while attaching VM when the HLOS retains access to VM.

  • CVE-2025-24917HigMay 23, 2025
    risk 0.51cvss 7.8epss 0.00

    In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.

  • CVE-2025-21470HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.

  • CVE-2025-21469HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.

  • CVE-2024-49842HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.

  • CVE-2025-27744HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.

  • CVE-2025-1865HigApr 4, 2025
    risk 0.51cvss 7.8epss 0.00

    The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM.

  • CVE-2025-24173HigMar 31, 2025
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.

  • CVE-2025-24076HigMar 11, 2025
    risk 0.51cvss 7.3epss 0.03

    Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

  • CVE-2024-9157HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to…

  • CVE-2025-21359HigFeb 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Security Feature Bypass Vulnerability

  • CVE-2024-35177HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. The wazuh-agent for Windows is vulnerable to a Local Privilege…