Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 47/65
7.9
CVE-2021-31581

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Co

7.9
CVE-2021-25502

A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows

7.8
CVE-2018-8044

K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process

7.8
CVE-2018-8724

K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileg

7.8
CVE-2018-9332

K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Incorrect Access Control. The impact is: gain privil

7.8
CVE-2018-9333

K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code

7.8
CVE-2021-0306

In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Andro

7.8
CVE-2021-1642

Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

7.8
CVE-2021-1648

Microsoft splwow64 Elevation of Privilege Vulnerability

7.8
CVE-2021-1649

Active Template Library Elevation of Privilege Vulnerability

7.8
CVE-2021-1650

Windows Runtime C++ Template Library Elevation of Privilege Vulnerability

7.8
CVE-2021-1651

Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability

7.8
CVE-2021-1652

Windows CSC Service Elevation of Privilege Vulnerability

7.8
CVE-2021-1653

Windows CSC Service Elevation of Privilege Vulnerability

7.8
CVE-2021-1654

Windows CSC Service Elevation of Privilege Vulnerability

7.8
CVE-2021-1655

Windows CSC Service Elevation of Privilege Vulnerability

7.8
CVE-2021-1657

Windows Fax Compose Form Remote Code Execution Vulnerability

7.8
CVE-2021-1659

Windows CSC Service Elevation of Privilege Vulnerability

7.8
CVE-2021-1662

Windows Event Tracing Elevation of Privilege Vulnerability

7.8
CVE-2021-1680

Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability

7.8
CVE-2021-1681

Windows WalletService Elevation of Privilege Vulnerability

7.8
CVE-2021-1686

Windows WalletService Elevation of Privilege Vulnerability

7.8
CVE-2021-1687

Windows WalletService Elevation of Privilege Vulnerability

7.8
CVE-2021-1688

Windows CSC Service Elevation of Privilege Vulnerability

7.8
CVE-2021-1689

Windows Multipoint Management Elevation of Privilege Vulnerability

7.8
CVE-2021-1690

Windows WalletService Elevation of Privilege Vulnerability

7.8
CVE-2021-1693

Windows CSC Service Elevation of Privilege Vulnerability

7.8
CVE-2021-1695

Windows Print Spooler Elevation of Privilege Vulnerability

7.8
CVE-2021-1697

Windows InstallService Elevation of Privilege Vulnerability

7.8
CVE-2021-1702

Windows Remote Procedure Call Runtime Elevation of Privilege Vulnerability

7.8
CVE-2021-1703

Windows Event Logging Service Elevation of Privilege Vulnerability

7.8
CVE-2021-0204

A sensitive information disclosure vulnerability in delta-export configuration utility (dexp) of Juniper Networks Junos

7.8
CVE-2021-0223

A local privilege escalation vulnerability in telnetd.real of Juniper Networks Junos OS may allow a locally authenticate

7.8
CVE-2020-6024

Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and

7.8
CVE-2020-26191

Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_

7.8
CVE-2021-23876

Bypass Remote Procedure call in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated priv

7.8
CVE-2021-0327

In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored bind

7.8
CVE-2021-26936

The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allow

7.8
CVE-2021-20075

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.

7.8
CVE-2021-25630

"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing a

7.8
CVE-2021-1698

Windows Win32k Elevation of Privilege Vulnerability

7.8
CVE-2021-1727

Windows Installer Elevation of Privilege Vulnerability

7.8
CVE-2021-1733

Sysinternals PsExec Elevation of Privilege Vulnerability

7.8
CVE-2021-24092

Microsoft Defender Elevation of Privilege Vulnerability

7.8
CVE-2021-24096

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2021-24102

Windows Event Tracing Elevation of Privilege Vulnerability

7.8
CVE-2021-1640

Windows Print Spooler Elevation of Privilege Vulnerability

7.8
CVE-2021-24090

Windows Error Reporting Elevation of Privilege Vulnerability

7.8
CVE-2021-27077

Windows Win32k Elevation of Privilege Vulnerability

7.8
CVE-2017-20002

The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/secu

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started