CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 112 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36725 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-32477 | Hig | 0.51 | 7.8 | 0.00 | Sep 29, 2023 | Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges. | ||
| CVE-2023-20224 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2023 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validation of… | ||
| CVE-2022-40964 | Hig | 0.51 | 7.9 | 0.00 | Aug 11, 2023 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2022-43702 | Hig | 0.51 | 7.8 | 0.00 | Jul 27, 2023 | When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code. | ||
| CVE-2023-33155 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-21670 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. | ||
| CVE-2021-25749 | Hig | 0.51 | 7.8 | 0.00 | May 24, 2023 | Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true. | ||
| CVE-2023-24905 | Hig | 0.51 | 7.8 | 0.01 | May 9, 2023 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2023-25496 | Hig | 0.51 | 7.8 | 0.00 | Apr 28, 2023 | A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges. | ||
| CVE-2023-26408 | Hig | 0.51 | 7.8 | 0.04 | Apr 12, 2023 | Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction… | ||
| CVE-2023-26406 | Hig | 0.51 | 7.8 | 0.04 | Apr 12, 2023 | Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction… | ||
| CVE-2023-28246 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2023 | Windows Registry Elevation of Privilege Vulnerability | ||
| CVE-2023-28051 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2023 | Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system. | ||
| CVE-2023-20065 | Hig | 0.51 | 7.8 | 0.00 | Mar 23, 2023 | A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An… | ||
| CVE-2023-1489 | Hig | 0.51 | 7.8 | 0.01 | Mar 18, 2023 | A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. Affected by this vulnerability is the function 0x9C402088 in the library WiseHDInfo64.dll of the component IoControlCode Handler. The manipulation leads to improper… | ||
| CVE-2023-0963 | Hig | 0.51 | 7.3 | 0.05 | Feb 22, 2023 | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be… | ||
| CVE-2023-24485 | Hig | 0.51 | 7.8 | 0.00 | Feb 16, 2023 | Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | ||
| CVE-2023-20927 | Hig | 0.51 | 7.8 | 0.00 | Feb 15, 2023 | In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-22960 | Hig | 0.51 | 7.5 | 0.28 | Jan 23, 2023 | Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency. |
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges.
- risk 0.51cvss 7.8epss 0.00
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validation of…
- risk 0.51cvss 7.9epss 0.00
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.
- risk 0.51cvss 7.8epss 0.00
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
- risk 0.51cvss 7.8epss 0.00
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
- risk 0.51cvss 7.8epss 0.01
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges.
- risk 0.51cvss 7.8epss 0.04
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…
- risk 0.51cvss 7.8epss 0.04
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…
- risk 0.51cvss 7.8epss 0.00
Windows Registry Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system.
- risk 0.51cvss 7.8epss 0.00
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An…
- risk 0.51cvss 7.8epss 0.01
A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. Affected by this vulnerability is the function 0x9C402088 in the library WiseHDInfo64.dll of the component IoControlCode Handler. The manipulation leads to improper…
- risk 0.51cvss 7.3epss 0.05
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be…
- risk 0.51cvss 7.8epss 0.00
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
- risk 0.51cvss 7.8epss 0.00
In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.51cvss 7.5epss 0.28
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.