VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 112 of 405
  • CVE-2023-36725HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-32477HigSep 29, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges.

  • CVE-2023-20224HigAug 16, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validation of…

  • CVE-2022-40964HigAug 11, 2023
    risk 0.51cvss 7.9epss 0.00

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-43702HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.

  • CVE-2023-33155HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

  • CVE-2023-21670HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.

  • CVE-2021-25749HigMay 24, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

  • CVE-2023-24905HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.01

    Remote Desktop Client Remote Code Execution Vulnerability

  • CVE-2023-25496HigApr 28, 2023
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges.

  • CVE-2023-26408HigApr 12, 2023
    risk 0.51cvss 7.8epss 0.04

    Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2023-26406HigApr 12, 2023
    risk 0.51cvss 7.8epss 0.04

    Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2023-28246HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Registry Elevation of Privilege Vulnerability

  • CVE-2023-28051HigApr 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system.

  • CVE-2023-20065HigMar 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An…

  • CVE-2023-1489HigMar 18, 2023
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. Affected by this vulnerability is the function 0x9C402088 in the library WiseHDInfo64.dll of the component IoControlCode Handler. The manipulation leads to improper…

  • CVE-2023-0963HigFeb 22, 2023
    risk 0.51cvss 7.3epss 0.05

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be…

  • CVE-2023-24485HigFeb 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.

  • CVE-2023-20927HigFeb 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-22960HigJan 23, 2023
    risk 0.51cvss 7.5epss 0.28

    Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.