Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 50/65
7.8
CVE-2021-42108

Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free B

7.8
CVE-2021-3576

Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a loca

7.8
CVE-2021-1118

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to

7.8
CVE-2021-41022

A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute p

7.8
CVE-2019-18916

A potential security vulnerability has been identified for HP LaserJet Solution Software (for certain HP LaserJet Printe

7.8
CVE-2021-36957

Windows Desktop Bridge Elevation of Privilege Vulnerability

7.8
CVE-2021-41366

Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability

7.8
CVE-2021-41367

NTFS Elevation of Privilege Vulnerability

7.8
CVE-2021-41370

NTFS Elevation of Privilege Vulnerability

7.8
CVE-2021-41377

Windows Fast FAT File System Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-42285

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2021-42286

Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability

7.8
CVE-2021-42322

Visual Studio Code Elevation of Privilege Vulnerability

7.8
CVE-2021-42956

Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclo

7.8
CVE-2021-35052

A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to Hi

7.8
CVE-2021-44019

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker

7.8
CVE-2021-44020

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker

7.8
CVE-2021-44021

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker

7.8
CVE-2021-37941

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a maliciou

7.8
CVE-2021-27445

Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges

7.8
CVE-2021-21911

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-Se

7.8
CVE-2021-21750

ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task mod

7.7
CVE-2021-25650

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us

7.6
CVE-2020-7467

In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 1

7.6
CVE-2021-28702

PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Region

7.5
CVE-2021-1694

Windows Update Stack Elevation of Privilege Vulnerability

7.5
CVE-2021-25442

Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Man

7.5
CVE-2021-29802

IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creat

7.5
CVE-2021-31350

An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on

7.5
CVE-2021-42282

Active Directory Domain Services Elevation of Privilege Vulnerability

7.5
CVE-2021-42291

Active Directory Domain Services Elevation of Privilege Vulnerability

7.5
CVE-2021-43828

PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper

7.3
CVE-2021-1685

Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

7.3
CVE-2021-1704

Windows Hyper-V Elevation of Privilege Vulnerability

7.3
CVE-2021-1706

Windows LUAFV Elevation of Privilege Vulnerability

7.3
CVE-2020-4184

IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, wh

7.3
CVE-2021-36945

Windows 10 Update Assistant Elevation of Privilege Vulnerability

7.2
CVE-2021-29792

IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and

7.2
CVE-2021-35534

Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM60

7.2
CVE-2021-43835

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who

7.1
CVE-2020-29031

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated

7.1
CVE-2021-1729

Windows Update Stack Setup Elevation of Privilege Vulnerability

7.1
CVE-2021-28692

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operati

7.1
CVE-2021-22326

A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this

7.1
CVE-2021-40354

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13

7.1
CVE-2021-38634

Microsoft Windows Update Client Elevation of Privilege Vulnerability

7.1
CVE-2021-31360

An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interp

7.1
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions start

7.0
CVE-2020-26181

Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation

7.0
CVE-2021-1682

Windows Kernel Elevation of Privilege Vulnerability

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started