CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,725 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 37 of 95
- CVE-2021-1447MEDIUMCVSS 6.7EG 6.72021-05-06
A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root. This vulnerability is due to a p…
- CVE-2021-1467MEDIUMCVSS 4.3EG 4.32021-04-08
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerabilit…
- CVE-2021-1477MEDIUMCVSS 4.3EG 4.32021-04-29
A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insuf…
- CVE-2021-1505CRITICALCVSS 9.8EG 9.82021-05-06
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privil…
- CVE-2021-1572HIGHCVSS 7.8EG 7.82021-08-04
A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root. To exploit this vulnerability, an attacker must have a va…
- CVE-2021-1579HIGHCVSS 8.1EG 8.82021-08-25
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read…
- CVE-2021-1640HIGHCVSS 7.8EG 7.82021-03-11
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2021-1642HIGHCVSS 7.8EG 7.82021-01-12
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
- CVE-2021-1646MEDIUMCVSS 6.6EG 6.62021-01-12
Windows WLAN Service Elevation of Privilege Vulnerability
- CVE-2021-1648HIGHCVSS 7.8EG 7.82021-01-12
Microsoft splwow64 Elevation of Privilege Vulnerability
- CVE-2021-1649HIGHCVSS 7.8EG 7.82021-01-12
Active Template Library Elevation of Privilege Vulnerability
- CVE-2021-1650HIGHCVSS 7.8EG 7.82021-01-12
Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
- CVE-2021-1651HIGHCVSS 7.8EG 7.82021-01-12
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
- CVE-2021-1652HIGHCVSS 7.8EG 7.82021-01-12
Windows CSC Service Elevation of Privilege Vulnerability
- CVE-2021-1653HIGHCVSS 7.8EG 7.82021-01-12
Windows CSC Service Elevation of Privilege Vulnerability
- CVE-2021-1654HIGHCVSS 7.8EG 7.82021-01-12
Windows CSC Service Elevation of Privilege Vulnerability
- CVE-2021-1655HIGHCVSS 7.8EG 7.82021-01-12
Windows CSC Service Elevation of Privilege Vulnerability
- CVE-2021-1657HIGHCVSS 7.8EG 7.82021-01-12
Windows Fax Compose Form Remote Code Execution Vulnerability
- CVE-2021-1659HIGHCVSS 7.8EG 7.82021-01-12
Windows CSC Service Elevation of Privilege Vulnerability
- CVE-2021-1661HIGHCVSS 7.8EG 7.82021-01-12
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-1662HIGHCVSS 7.8EG 7.82021-01-12
Windows Event Tracing Elevation of Privilege Vulnerability
- CVE-2021-1675CRITICALCVSS 7.8EG 9.0⚠ KEV2021-06-08
Windows Print Spooler Remote Code Execution Vulnerability
- CVE-2021-1680HIGHCVSS 7.8EG 7.82021-01-12
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
- CVE-2021-1681HIGHCVSS 7.8EG 7.82021-01-12
Windows WalletService Elevation of Privilege Vulnerability
- CVE-2021-1682HIGHCVSS 7.0EG 7.02021-01-12
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2021-1685HIGHCVSS 7.3EG 7.32021-01-12
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
- CVE-2021-1686HIGHCVSS 7.8EG 7.82021-01-12
Windows WalletService Elevation of Privilege Vulnerability
- CVE-2021-1687HIGHCVSS 7.8EG 7.82021-01-12
Windows WalletService Elevation of Privilege Vulnerability
- CVE-2021-1688HIGHCVSS 7.8EG 7.82021-01-12
Windows CSC Service Elevation of Privilege Vulnerability
- CVE-2021-1689HIGHCVSS 7.8EG 7.82021-01-12
Windows Multipoint Management Elevation of Privilege Vulnerability
- CVE-2021-1690HIGHCVSS 7.8EG 7.82021-01-12
Windows WalletService Elevation of Privilege Vulnerability
- CVE-2021-1693HIGHCVSS 7.8EG 7.82021-01-12
Windows CSC Service Elevation of Privilege Vulnerability
- CVE-2021-1694HIGHCVSS 7.5EG 7.52021-01-12
Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2021-1695HIGHCVSS 7.8EG 7.82021-01-12
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2021-1697HIGHCVSS 7.8EG 7.82021-01-12
Windows InstallService Elevation of Privilege Vulnerability
- CVE-2021-1698HIGHCVSS 7.8EG 7.82021-02-25
Windows Win32k Elevation of Privilege Vulnerability
- CVE-2021-1702HIGHCVSS 7.8EG 7.82021-01-12
Windows Remote Procedure Call Runtime Elevation of Privilege Vulnerability
- CVE-2021-1703HIGHCVSS 7.8EG 7.82021-01-12
Windows Event Logging Service Elevation of Privilege Vulnerability
- CVE-2021-1704HIGHCVSS 7.3EG 7.82021-01-12
Windows Hyper-V Elevation of Privilege Vulnerability
- CVE-2021-1706HIGHCVSS 7.3EG 7.32021-01-12
Windows LUAFV Elevation of Privilege Vulnerability
- CVE-2021-1709HIGHCVSS 7.0EG 7.02021-01-12
Windows Win32k Elevation of Privilege Vulnerability
- CVE-2021-1712HIGHCVSS 8.0EG 8.02021-01-12
Microsoft SharePoint Elevation of Privilege Vulnerability
- CVE-2021-1719HIGHCVSS 8.0EG 8.02021-01-12
Microsoft SharePoint Elevation of Privilege Vulnerability
- CVE-2021-1727HIGHCVSS 7.8EG 7.82021-02-25
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-1728HIGHCVSS 8.8EG 8.82021-02-25
System Center Operations Manager Elevation of Privilege Vulnerability
- CVE-2021-1729HIGHCVSS 7.1EG 7.12021-03-11
Windows Update Stack Setup Elevation of Privilege Vulnerability
- CVE-2021-1732CRITICALCVSS 7.8EG 9.0⚠ KEV2021-02-25
Windows Win32k Elevation of Privilege Vulnerability
- CVE-2021-1733HIGHCVSS 7.8EG 7.82021-02-25
Sysinternals PsExec Elevation of Privilege Vulnerability
- CVE-2021-1750HIGHCVSS 7.8EG 7.82021-04-02
Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. An application may be able…
- CVE-2021-1782CRITICALCVSS 7.0EG 9.0⚠ KEV2021-04-02
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application …
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →