Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 49/65
7.8
CVE-2021-1572

A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the

7.8
CVE-2021-21567

Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated use

7.8
CVE-2021-34471

Microsoft Defender Elevation of Privilege Vulnerability

7.8
CVE-2021-34483

Windows Print Spooler Elevation of Privilege Vulnerability

7.8
CVE-2021-34537

Windows Bluetooth Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-36927

Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability

7.8
CVE-2021-37345

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the

7.8
CVE-2021-34745

A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local us

7.8
CVE-2021-24038

Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle

7.8
CVE-2021-1813

A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security

7.8
CVE-2021-1839

The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021

7.8
CVE-2021-1853

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A local attacker

7.8
CVE-2021-1868

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Se

7.8
CVE-2021-36963

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-36964

Windows Event Tracing Elevation of Privilege Vulnerability

7.8
CVE-2021-36966

Windows Subsystem for Linux Elevation of Privilege Vulnerability

7.8
CVE-2021-36968

Windows DNS Elevation of Privilege Vulnerability

7.8
CVE-2021-36973

Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability

7.8
CVE-2021-36974

Windows SMB Elevation of Privilege Vulnerability

7.8
CVE-2021-36975

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2021-38625

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2021-38626

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2021-38628

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

7.8
CVE-2021-38630

Windows Event Tracing Elevation of Privilege Vulnerability

7.8
CVE-2021-38633

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-38638

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

7.8
CVE-2021-38639

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2021-38667

Windows Print Spooler Elevation of Privilege Vulnerability

7.8
CVE-2021-38671

Windows Print Spooler Elevation of Privilege Vulnerability

7.8
CVE-2021-40447

Windows Print Spooler Elevation of Privilege Vulnerability

7.8
CVE-2021-34411

During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to lau

7.8
CVE-2021-34412

During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possibl

7.8
CVE-2021-26441

Storage Spaces Controller Elevation of Privilege Vulnerability

7.8
CVE-2021-40443

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-40466

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-40467

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-40470

DirectX Graphics Kernel Elevation of Privilege Vulnerability

7.8
CVE-2021-40477

Windows Event Tracing Elevation of Privilege Vulnerability

7.8
CVE-2021-40478

Storage Spaces Controller Elevation of Privilege Vulnerability

7.8
CVE-2021-40488

Storage Spaces Controller Elevation of Privilege Vulnerability

7.8
CVE-2021-40489

Storage Spaces Controller Elevation of Privilege Vulnerability

7.8
CVE-2021-41335

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2021-41345

Storage Spaces Controller Elevation of Privilege Vulnerability

7.8
CVE-2021-41347

Windows AppX Deployment Service Elevation of Privilege Vulnerability

7.8
CVE-2021-40854

AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Cha

7.8
CVE-2021-31359

A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privile

7.8
CVE-2021-42104

Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0

7.8
CVE-2021-42105

Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0

7.8
CVE-2021-42106

Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0

7.8
CVE-2021-42107

Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started