CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 109 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-49707 | Hig | 0.51 | 7.9 | 0.00 | Aug 12, 2025 | Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. | ||
| CVE-2025-27062 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while handling client exceptions, allowing unauthorized channel access. | ||
| CVE-2025-50777 | Hig | 0.51 | 7.8 | 0.00 | Jul 30, 2025 | The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials… | ||
| CVE-2025-47993 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-23365 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and… | ||
| CVE-2025-27689 | Hig | 0.51 | 7.8 | 0.00 | Jun 12, 2025 | Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||
| CVE-2025-47962 | Hig | 0.51 | 7.8 | 0.02 | Jun 10, 2025 | Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-32714 | Hig | 0.51 | 7.8 | 0.01 | Jun 10, 2025 | Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-53010 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption may occur while attaching VM when the HLOS retains access to VM. | ||
| CVE-2025-24917 | Hig | 0.51 | 7.8 | 0.00 | May 23, 2025 | In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation. | ||
| CVE-2025-21470 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter. | ||
| CVE-2025-21469 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2025-27744 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-1865 | — | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2025 | The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM. | |
| CVE-2025-24173 | Hig | 0.51 | 7.8 | 0.00 | Mar 31, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox. | ||
| CVE-2025-24076 | Hig | 0.51 | 7.3 | 0.03 | Mar 11, 2025 | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-9157 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to… | ||
| CVE-2025-21359 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Windows Kernel Security Feature Bypass Vulnerability | ||
| CVE-2024-35177 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. The wazuh-agent for Windows is vulnerable to a Local Privilege… |
- risk 0.51cvss 7.9epss 0.00
Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling client exceptions, allowing unauthorized channel access.
- risk 0.51cvss 7.8epss 0.00
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials…
- risk 0.51cvss 7.8epss 0.00
Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and…
- risk 0.51cvss 7.8epss 0.00
Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- risk 0.51cvss 7.8epss 0.02
Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
- risk 0.51cvss 7.8epss 0.00
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.01
Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM.
- risk 0.51cvss 7.8epss 0.00
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
- risk 0.51cvss 7.3epss 0.03
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to…
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.00
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. The wazuh-agent for Windows is vulnerable to a Local Privilege…