Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free B
Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a loca
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to
A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute p
A potential security vulnerability has been identified for HP LaserJet Solution Software (for certain HP LaserJet Printe
Windows Desktop Bridge Elevation of Privilege Vulnerability
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
NTFS Elevation of Privilege Vulnerability
NTFS Elevation of Privilege Vulnerability
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclo
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to Hi
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a maliciou
Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-Se
ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task mod
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us
In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 1
PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Region
Windows Update Stack Elevation of Privilege Vulnerability
Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Man
IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creat
An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on
Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
Windows LUAFV Elevation of Privilege Vulnerability
IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, wh
Windows 10 Update Assistant Elevation of Privilege Vulnerability
IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and
Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM60
Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated
Windows Update Stack Setup Elevation of Privilege Vulnerability
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operati
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13
Microsoft Windows Update Client Elevation of Privilege Vulnerability
An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interp
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions start
Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation
Windows Kernel Elevation of Privilege Vulnerability
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started