VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 110 of 405
  • CVE-2024-43600HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Elevation of Privilege Vulnerability

  • CVE-2024-49600HigDec 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges.

  • CVE-2024-43530HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Update Stack Elevation of Privilege Vulnerability

  • CVE-2024-45334HigOct 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that could allow unauthorized access to product configurations and functions.

  • CVE-2024-43590HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Visual C++ Redistributable Installer Elevation of Privilege Vulnerability

  • CVE-2024-43503HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft SharePoint Elevation of Privilege Vulnerability

  • CVE-2024-38016HigSep 19, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2024-43492HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

  • CVE-2024-26022HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-25576HigAug 14, 2024
    risk 0.51cvss 7.9epss 0.00

    improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access.

  • CVE-2024-38163HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Update Stack Elevation of Privilege Vulnerability

  • CVE-2024-38195HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Azure CycleCloud Remote Code Execution Vulnerability

  • CVE-2024-38162HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Azure Connected Machine Agent Elevation of Privilege Vulnerability

  • CVE-2024-41309HigAug 7, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.

  • CVE-2024-41308HigAug 7, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.

  • CVE-2024-40812HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, visionOS 1.3, watchOS 10.6. A shortcut may be able to bypass Internet permission…

  • CVE-2024-31320HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2024-38100HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.05

    Windows File Explorer Elevation of Privilege Vulnerability

  • CVE-2024-34112HigJun 13, 2024
    risk 0.51cvss 7.5epss 0.24

    ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could exploit this vulnerability to gain unauthorized access to sensitive files or data. Exploitation of this…

  • CVE-2024-37289HigJun 10, 2024
    risk 0.51cvss 7.8epss 0.01

    An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…