CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 110 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-43600 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Microsoft Office Elevation of Privilege Vulnerability | ||
| CVE-2024-49600 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2024 | Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges. | ||
| CVE-2024-43530 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2024-45334 | Hig | 0.51 | 7.8 | 0.00 | Oct 22, 2024 | Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that could allow unauthorized access to product configurations and functions. | ||
| CVE-2024-43590 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2024 | Visual C++ Redistributable Installer Elevation of Privilege Vulnerability | ||
| CVE-2024-43503 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Microsoft SharePoint Elevation of Privilege Vulnerability | ||
| CVE-2024-38016 | Hig | 0.51 | 7.8 | 0.01 | Sep 19, 2024 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2024-43492 | Hig | 0.51 | 7.8 | 0.00 | Sep 10, 2024 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | ||
| CVE-2024-26022 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2024 | Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2024-25576 | Hig | 0.51 | 7.9 | 0.00 | Aug 14, 2024 | improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access. | ||
| CVE-2024-38163 | Hig | 0.51 | 7.8 | 0.01 | Aug 14, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2024-38195 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Azure CycleCloud Remote Code Execution Vulnerability | ||
| CVE-2024-38162 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | ||
| CVE-2024-41309 | Hig | 0.51 | 7.8 | 0.00 | Aug 7, 2024 | An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system. | ||
| CVE-2024-41308 | Hig | 0.51 | 7.8 | 0.00 | Aug 7, 2024 | An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system. | ||
| CVE-2024-40812 | Hig | 0.51 | 7.8 | 0.00 | Jul 29, 2024 | A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, visionOS 1.3, watchOS 10.6. A shortcut may be able to bypass Internet permission… | ||
| CVE-2024-31320 | Hig | 0.51 | 7.8 | 0.00 | Jul 9, 2024 | In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed… | ||
| CVE-2024-38100 | Hig | 0.51 | 7.8 | 0.05 | Jul 9, 2024 | Windows File Explorer Elevation of Privilege Vulnerability | ||
| CVE-2024-34112 | Hig | 0.51 | 7.5 | 0.24 | Jun 13, 2024 | ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could exploit this vulnerability to gain unauthorized access to sensitive files or data. Exploitation of this… | ||
| CVE-2024-37289 | Hig | 0.51 | 7.8 | 0.01 | Jun 10, 2024 | An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… |
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges.
- risk 0.51cvss 7.8epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that could allow unauthorized access to product configurations and functions.
- risk 0.51cvss 7.8epss 0.00
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SharePoint Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.9epss 0.00
improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Azure CycleCloud Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
- risk 0.51cvss 7.8epss 0.00
An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
- risk 0.51cvss 7.8epss 0.00
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, visionOS 1.3, watchOS 10.6. A shortcut may be able to bypass Internet permission…
- risk 0.51cvss 7.8epss 0.00
In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- risk 0.51cvss 7.8epss 0.05
Windows File Explorer Elevation of Privilege Vulnerability
- risk 0.51cvss 7.5epss 0.24
ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could exploit this vulnerability to gain unauthorized access to sensitive files or data. Exploitation of this…
- risk 0.51cvss 7.8epss 0.01
An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…