CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 62 of 99
- CVE-2023-1694HIGHCVSS 7.5EG 7.52023-05-20
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2023-1762HIGHCVSS 8.8EG 8.82023-03-31
Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- CVE-2023-1966HIGHCVSS 7.4EG 7.42023-04-28
Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an a…
- CVE-2023-20048CRITICALCVSS 9.9EG 9.92023-11-01
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) devi…
- CVE-2023-20136MEDIUMCVSS 4.3EG 4.32023-06-28
A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid…
- CVE-2023-20193MEDIUMCVSS 6.0EG 6.02023-09-07
A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit t…
- CVE-2023-20194MEDIUMCVSS 4.9EG 4.92023-09-07
A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administ…
- CVE-2023-20216MEDIUMCVSS 4.4EG 4.42023-08-03
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect imp…
- CVE-2023-20235MEDIUMCVSS 6.5EG 6.52023-10-04
A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system…
- CVE-2023-20266MEDIUMCVSS 6.5EG 6.52023-08-30
A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, rem…
- CVE-2023-20274MEDIUMCVSS 6.3EG 6.32023-11-21
A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient permissions that are set by the P…
- CVE-2023-20563HIGHCVSS 7.8EG 7.82023-11-14
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
- CVE-2023-20565HIGHCVSS 7.8EG 7.82023-11-14
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
- CVE-2023-20598HIGHCVSS 7.8EG 7.82023-10-17
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitr…
- CVE-2023-20655HIGHCVSS 7.8EG 7.82023-04-06
In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-20680MEDIUMCVSS 6.7EG 6.72023-04-06
In adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS076…
- CVE-2023-20854HIGHCVSS 8.4EG 8.42023-02-03
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on whic…
- CVE-2023-20995HIGHCVSS 7.8EG 7.82023-03-24
In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
- CVE-2023-21068HIGHCVSS 7.8EG 7.82023-03-24
In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalation of privilege after preparing the device, hiding the warning, and passing the phone to a…
- CVE-2023-21113HIGHCVSS 7.8EG 7.82024-07-09
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-21114HIGHCVSS 7.8EG 7.82024-07-09
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-21269HIGHCVSS 7.8EG 7.82023-08-14
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges need…
- CVE-2023-21272HIGHCVSS 7.8EG 7.82023-08-14
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2023-21343HIGHCVSS 7.8EG 7.82023-10-30
In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita…
- CVE-2023-21374HIGHCVSS 7.8EG 7.82023-10-30
In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit…
- CVE-2023-21376MEDIUMCVSS 5.5EG 5.52023-10-30
In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-21396HIGHCVSS 7.8EG 7.82023-10-30
In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-21397HIGHCVSS 7.8EG 7.82023-10-30
In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2023-21421HIGHCVSS 5.9EG 7.82023-02-09
Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.
- CVE-2023-21458MEDIUMCVSS 6.2EG 6.22023-03-16
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
- CVE-2023-21512LOWCVSS 2.4EG 2.42023-06-28
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
- CVE-2023-21513MEDIUMCVSS 6.1EG 6.12023-06-28
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
- CVE-2023-21531HIGHCVSS 7.0EG 7.02023-01-10
Azure Service Fabric Container Elevation of Privilege Vulnerability
- CVE-2023-21542HIGHCVSS 7.0EG 7.02023-01-10
Windows Installer Elevation of Privilege Vulnerability
- CVE-2023-21549HIGHCVSS 8.8EG 8.82023-01-10
Windows SMB Witness Service Elevation of Privilege Vulnerability
- CVE-2023-21551HIGHCVSS 7.8EG 7.82023-01-10
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
- CVE-2023-21552HIGHCVSS 7.8EG 7.82023-01-10
Windows GDI Elevation of Privilege Vulnerability
- CVE-2023-21561HIGHCVSS 7.8EG 8.82023-01-10
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
- CVE-2023-21730HIGHCVSS 7.8EG 7.82023-01-10
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
- CVE-2023-21755HIGHCVSS 7.8EG 7.82023-01-10
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21772HIGHCVSS 7.8EG 7.82023-01-10
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21773HIGHCVSS 7.8EG 7.82023-01-10
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21774HIGHCVSS 7.8EG 7.82023-01-10
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21777HIGHCVSS 8.7EG 8.72023-02-14
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
- CVE-2023-21848HIGHCVSS 8.8EG 8.82023-01-18
Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Admin Configuration). The supported version that is affected is 3.0.3.1.0. Easily exploitable vulnerability allows low privi…
- CVE-2023-21896HIGHCVSS 7.0EG 7.02023-04-18
Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure w…
- CVE-2023-21987HIGHCVSS 7.8EG 7.82023-04-18
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Difficult to exploit vulnerability allows low privileged attacker …
- CVE-2023-21990HIGHCVSS 8.2EG 8.22023-04-18
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker w…
- CVE-2023-22023HIGHCVSS 7.8EG 7.82023-07-18
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastru…
- CVE-2023-22099HIGHCVSS 8.2EG 8.22023-10-17
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.12. Easily exploitable vulnerability allows high privileged attacker with logon to the inf…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →