VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 111 of 405
  • CVE-2022-48683HigJun 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may be able to break out of its sandbox.

  • CVE-2023-52712HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM…

  • CVE-2023-52711HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM…

  • CVE-2023-43748HigMay 16, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-34099HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2024-0025HigMay 7, 2024
    risk 0.51cvss 7.8epss 0.00

    In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-33673HigApr 26, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.

  • CVE-2024-21103HigApr 16, 2024
    risk 0.51cvss 7.8epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2024-21436HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2024-21418HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability

  • CVE-2024-21805HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's…

  • CVE-2024-0036HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution…

  • CVE-2023-35121HigFeb 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25777HigFeb 14, 2024
    risk 0.51cvss 7.9epss 0.00

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-44283HigFeb 14, 2024
    risk 0.51cvss 7.8epss 0.00

    In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege…

  • CVE-2023-7025HigDec 21, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the function init_kcm of the component DBus Handler. The manipulation leads to improper access controls. Attacking locally is a…

  • CVE-2023-49694HigNov 29, 2023
    risk 0.51cvss 7.8epss 0.01

    A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.

  • CVE-2023-28397HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access.

  • CVE-2023-31019HigNov 2, 2023
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's…

  • CVE-2023-36790HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability