Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges
The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninst
In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due
In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary ap
In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications se
An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges v
An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive informat
An issue in TeraByte Unlimited Image for Windows v.3.64.0.0 and before and fixed in v.4.0.0.0 allows a local attacker to
An issue in MarvinTest Solutions Hardware Access Driver v.5.0.3.0 and before and fixed in v.5.0.4.0 allows a local attac
An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a c
The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 1
Trend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local atta
In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This coul
In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of
Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect se
The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local
Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute ar
Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute
Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati
In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in
In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. T
In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check
In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to
In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association withou
In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Se
In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjack
In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This
In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Privilege escalation in uberAgent
Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be call
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 1
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ven
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ven
Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is int
In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be vis
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the
The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This c
Windows Installer Elevation of Privilege Vulnerability
In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users du
In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow.
In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This co
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started