CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,725 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 34 of 95
- CVE-2020-8092LOWCVSS 1.6EG 1.62020-01-30
A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud. This issue affects: Bitdefender Bitdefender…
- CVE-2020-8113CRITICALCVSS 9.8EG 9.82020-03-06
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
- CVE-2020-8126HIGHCVSS 7.8EG 7.82020-02-07
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and became administrat…
- CVE-2020-8145MEDIUMCVSS 6.5EG 6.52020-04-01
The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM…
- CVE-2020-8146HIGHCVSS 7.8EG 7.82020-04-01
In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is runn…
- CVE-2020-8179MEDIUMCVSS 4.1EG 4.12020-07-02
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
- CVE-2020-8197HIGHCVSS 8.8EG 8.82020-07-10
Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.
- CVE-2020-8199HIGHCVSS 7.8EG 7.82020-07-10
Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.
- CVE-2020-8223MEDIUMCVSS 6.5EG 6.52020-10-05
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
- CVE-2020-8239CRITICALCVSS 9.8EG 9.82020-10-28
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.
- CVE-2020-8247HIGHCVSS 8.8EG 8.82020-09-18
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.…
- CVE-2020-8248HIGHCVSS 7.8EG 7.82020-10-28
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
- CVE-2020-8250HIGHCVSS 7.8EG 7.82020-10-28
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
- CVE-2020-8257CRITICALCVSS 9.8EG 9.82020-12-14
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks
- CVE-2020-8258HIGHCVSS 7.5EG 7.52020-12-14
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.
- CVE-2020-8269HIGHCVSS 8.8EG 8.82020-11-16
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9
- CVE-2020-8275MEDIUMCVSS 4.3EG 4.32021-01-06
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the…
- CVE-2020-8283HIGHCVSS 8.8EG 8.82020-12-14
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7…
- CVE-2020-8290HIGHCVSS 7.8EG 7.82020-12-27
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for loc…
- CVE-2020-8300MEDIUMCVSS 6.5EG 6.52021-06-16
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a vali…
- CVE-2020-8318HIGHCVSS 7.3EG 7.32020-04-14
A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could allow an authenticated user to execute code with elevated privileges.
- CVE-2020-8319HIGHCVSS 7.3EG 7.32020-04-14
A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated user to execute code with elevated privileges.
- CVE-2020-8320MEDIUMCVSS 6.4EG 6.42020-06-09
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
- CVE-2020-8327HIGHCVSS 7.3EG 7.32020-04-14
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to execute code with eleva…
- CVE-2020-8351HIGHCVSS 7.8EG 7.82020-11-30
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
- CVE-2020-8474HIGHCVSS 7.8EG 7.82020-04-22
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.
- CVE-2020-8494HIGHCVSS 8.8EG 8.82020-01-30
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser servlet allows an attacker with Timekeeper, Master Timekeeper, or HR Admin privileges to gain unauthorized administrative…
- CVE-2020-8623HIGHCVSS 7.5EG 7.52020-08-21
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a…
- CVE-2020-8624MEDIUMCVSS 4.3EG 4.32020-08-21
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privi…
- CVE-2020-8635HIGHCVSS 7.8EG 7.82020-03-07
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges withi…
- CVE-2020-8655CRITICALCVSS 7.8EG 9.0⚠ KEV2020-02-07
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to run arbitrary commands as root via a crafted NSE script for nmap 7.
- CVE-2020-8675MEDIUMCVSS 6.8EG 6.82020-06-15
Insufficient control flow management in firmware build and signing tool for Intel(R) Innovation Engine before version 1.0.859 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
- CVE-2020-8676MEDIUMCVSS 6.7EG 6.72020-11-12
Improper access control in the Intel(R) Visual Compute Accelerator 2, all versions, may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2020-8684MEDIUMCVSS 6.7EG 6.72020-08-13
Improper access control in firmware for Intel(R) PAC with Arria(R) 10 GX FPGA before Intel Acceleration Stack version 1.2.1 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2020-8690MEDIUMCVSS 6.7EG 6.72020-11-12
Protection mechanism failure in Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
- CVE-2020-8691MEDIUMCVSS 6.7EG 6.72020-11-12
A logic issue in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
- CVE-2020-8692MEDIUMCVSS 6.7EG 6.72020-11-12
Insufficient access control in the firmware of the Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
- CVE-2020-8736HIGHCVSS 7.8EG 7.82020-08-13
Improper access control in subsystem for the Intel(R) Computing Improvement Program before version 2.4.5718 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-8745MEDIUMCVSS 6.8EG 6.82020-11-12
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated …
- CVE-2020-8808HIGHCVSS 7.8EG 7.82020-02-07
The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequentl…
- CVE-2020-8873MEDIUMCVSS 6.7EG 6.72020-03-23
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to …
- CVE-2020-8948HIGHCVSS 7.8EG 7.82020-04-15
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to…
- CVE-2020-9024CRITICALCVSS 9.8EG 9.82020-02-17
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.
- CVE-2020-9043HIGHCVSS 8.8EG 8.82020-02-17
The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.
- CVE-2020-9046HIGHCVSS 8.8EG 8.82020-05-26
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
- CVE-2020-9072MEDIUMCVSS 6.7EG 6.72020-04-27
Huawei OSD product with versions earlier than OSD_uwp_9.0.32.0 have a local privilege escalation vulnerability. An authenticated, local attacker can constructs a specific file path to exploit this vulnerability. Successful exploitation may…
- CVE-2020-9078HIGHCVSS 7.8EG 7.82020-08-10
FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege…
- CVE-2020-9080HIGHCVSS 7.8EG 7.82024-12-27
There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. Successful exploitation may lead to local privilege escalati…
- CVE-2020-9112HIGHCVSS 7.8EG 7.82020-10-19
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of the business functions of the device. An attacker could exploit this vulnerability to acc…
- CVE-2020-9114HIGHCVSS 7.8EG 7.82020-12-01
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privile…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →