ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11
This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16. An app may
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 1
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to mo
starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted fi
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible su
A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6,
An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated
Windows Accounts Picture Elevation of Privilege Vulnerability
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their us
In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error i
In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QE
A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During installation, an EXE gets executed out of C:\Wi
An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens No
In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code exe
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info fi
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a mali
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a loc
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decry
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDM
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windo
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user runn
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain so
During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with th
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could a
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could a
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could a
Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl
A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a mali
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a mali
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported vers
Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid,
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the back
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead
Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attack
Local privilege escalation due to insecure driver communication port permissions. The following products are affected: A
Local privilege escalation due to insecure driver communication port permissions. The following products are affected: A
BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to gain
In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started