Storage Spaces Direct Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Defender Credential Guard Elevation of Privilege Vulnerability
In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escal
A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all us
An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with loc
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPa
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially a
UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode i
A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a
A local privilege escalation vulnerability in UI Desktop for Windows (Version 0.55.1.2 and earlier) allows a malicious a
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to gain ro
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big S
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, ma
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An
RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI inst
NuGet Client Elevation of Privilege Vulnerability
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conj
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, ma
This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege esca
INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via c
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image:
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is
wfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privil
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code
An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 throug
A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application,
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local ad
Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitatio
The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerabi
Cilium is open source software for providing and securing network connectivity and loadbalancing between application wor
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure cause
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions
An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Pro
Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpag
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of th
A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet commu
A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SIN
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started