CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

806
Total CVEs
170
Critical
546
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 46
3 Huawei 26
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Fortinet 8
9 Apache 7
10 Citrix 7

All Improper Privilege Management CVEs (806)

CVE-2023-41036
7.8

This vulnerability in MacVim allows privilege escalation to root via insecure interprocess communication (IPC) using Apple's Distributed Objects. Any ...

Nov 7, 2023
CVE-2023-21374
7.8

This vulnerability allows attackers to bypass factory reset protection on Android devices, potentially gaining unauthorized access to devices that sho...

Oct 30, 2023
CVE-2023-21396
7.8

This vulnerability in Android's Activity Manager allows malicious apps to launch background activities without user interaction due to a logic error. ...

Oct 30, 2023
CVE-2023-21343
7.8

This vulnerability in Android's ActivityStarter component allows malicious apps to launch background activities without user interaction through an un...

Oct 30, 2023
CVE-2023-34057
7.8

CVE-2023-34057 is a local privilege escalation vulnerability in VMware Tools that allows a user with local access to a guest virtual machine to elevat...

Oct 27, 2023
CVE-2023-5671
7.8

CVE-2023-5671 is a privilege escalation vulnerability in HP Print and Scan Doctor for Windows that allows local attackers to gain elevated system priv...

Oct 25, 2023
CVE-2023-46277
7.8

CVE-2023-46277 is a privilege escalation vulnerability in the 'please' (pleaser) sudo alternative tool versions through 0.5.4. It allows local attacke...

Oct 20, 2023
CVE-2023-27795
7.8

This vulnerability in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to escalate privileges using a static XOR key. Attackers with local ...

Oct 19, 2023
CVE-2023-45883
7.8

This vulnerability allows standard Windows users to escalate privileges to SYSTEM level by triggering a software repair process in Qumu Multicast Exte...

Oct 19, 2023
CVE-2023-38817
7.8

This vulnerability in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to escalate privileges via a crafted command to the echo_driver.sy...

Oct 11, 2023
CVE-2023-26236
7.8

This vulnerability allows local attackers to escalate privileges on Windows systems running WatchGuard EPDR 8.0.21.0002. By sending a specially crafte...

Oct 5, 2023
CVE-2023-35676
7.8

This vulnerability allows local privilege escalation on Android devices through an unsafe PendingIntent in the Quick Share functionality. Attackers ca...

Sep 11, 2023
CVE-2023-35667
7.8

This vulnerability in Android's Settings app allows attackers to hide approved notification listeners from the settings interface due to a logic error...

Sep 11, 2023
CVE-2023-32426
7.8

This CVE describes a privilege escalation vulnerability in macOS where a malicious application could exploit a logic issue to gain root privileges. It...

Sep 6, 2023
CVE-2023-41743
7.8

This CVE describes a local privilege escalation vulnerability in Acronis products for Windows. It allows a local low-privileged user to gain SYSTEM-le...

Aug 31, 2023
CVE-2022-45451
7.8

This CVE describes a local privilege escalation vulnerability in Acronis products for Windows. It allows a local attacker with low privileges to gain ...

Aug 31, 2023
CVE-2023-32487
7.8

Dell PowerScale OneFS versions 8.2.x through 9.5.0.x contain a local privilege escalation vulnerability. A low-privileged local attacker could exploit...

Aug 16, 2023
CVE-2023-21269
7.8

This Android vulnerability allows malicious apps to launch activities into Picture-in-Picture (PiP) mode from the background by bypassing background a...

Aug 14, 2023
CVE-2023-3160
7.8

This vulnerability in ESET security software allows attackers to abuse file operations during module updates to delete or move files without proper pe...

Aug 14, 2023
CVE-2023-31432
7.8

This vulnerability allows non-privileged users to escalate their privileges to root by manipulating passwords or other variables through specific comm...

Aug 2, 2023
CVE-2023-3514
7.8

This vulnerability allows local attackers to escalate privileges to SYSTEM level on Windows systems running vulnerable versions of RazerCentral. Attac...

Jul 14, 2023
CVE-2023-34146
7.8

This vulnerability in Trend Micro Apex One and Apex One as a Service allows a local attacker with low-privileged code execution to escalate privileges...

Jun 26, 2023
CVE-2023-34148
7.8

This vulnerability in Trend Micro Apex One and Apex One as a Service allows a local attacker with low-privileged code execution to escalate privileges...

Jun 26, 2023
CVE-2023-30601
7.8

This vulnerability allows users with JMX access to escalate privileges and execute arbitrary commands as the Apache Cassandra service account when ena...

May 30, 2023
CVE-2023-26245
7.8

This vulnerability allows attackers to modify the AppUpgrade binary file in Hyundai Gen5W_L in-vehicle infotainment systems to bypass firmware version...

Apr 27, 2023
CVE-2023-21987
7.8

This vulnerability in Oracle VM VirtualBox allows a low-privileged attacker with local access to the host system to potentially compromise the Virtual...

Apr 18, 2023
CVE-2023-27651
7.8

This vulnerability in Ego Studio SuperClean allows attackers to escalate privileges by manipulating the update_info field in the _default_.xml file. I...

Apr 14, 2023
CVE-2022-48226
7.8

This vulnerability allows local privilege escalation in Acuant AcuFill SDK installations. During installation, the software executes an EXE from C:\Wi...

Apr 4, 2023
CVE-2023-20995
7.8

This vulnerability allows bypassing fingerprint authentication on Android 13 devices due to a logic error in the CustomizedSensor.cpp file. An attacke...

Mar 24, 2023
CVE-2023-23412
7.8

This Windows vulnerability allows an authenticated attacker to gain SYSTEM-level privileges by exploiting improper handling of account picture changes...

Mar 14, 2023
CVE-2023-26604
7.8

This vulnerability allows local privilege escalation when users run 'systemctl status' via Sudo in certain configurations. Attackers can escape from t...

Mar 3, 2023
CVE-2022-27677
7.8

This vulnerability allows low-privileged users to modify files during AMD Ryzen Master installation, potentially leading to privilege escalation and a...

Mar 1, 2023
CVE-2022-42455
7.8

This vulnerability in ASUS EC Tool driver allows local users to gain elevated privileges by exploiting unprivileged IOCTL calls that provide raw read/...

Feb 15, 2023
CVE-2023-25011
7.8

This vulnerability allows a standard user to write to the Windows registry with administrator privileges through NEC's PC settings tool. Attackers can...

Feb 15, 2023
CVE-2022-38777
7.8

CVE-2022-38777 is a privilege escalation vulnerability in Elastic Endpoint Security for Windows. Unprivileged users can exploit the rollback feature t...

Feb 8, 2023
CVE-2020-24307
7.8

CVE-2020-24307 is a privilege escalation vulnerability in mRemoteNG v1.76.20 that allows attackers to execute arbitrary code with elevated privileges ...

Feb 2, 2023
CVE-2022-3990
7.8

CVE-2022-3990 is a privilege escalation vulnerability in HPSFViewer that could allow attackers to gain elevated privileges on affected systems. It aff...

Feb 1, 2023
CVE-2021-3809
7.8

This CVE describes vulnerabilities in HP PC BIOS/UEFI firmware that could allow attackers to execute arbitrary code with high privileges. Affected sys...

Feb 1, 2023
CVE-2021-3439
7.8

This CVE describes a BIOS firmware vulnerability in certain HP Workstation products that could allow local attackers to execute arbitrary code with el...

Feb 1, 2023
CVE-2022-30526
7.8

This CVE describes a local privilege escalation vulnerability in Zyxel firewall CLI commands where a local attacker can execute OS commands with root ...

Jul 19, 2022
CVE-2020-21046
7.8

This CVE describes a local privilege escalation vulnerability in EagleGet Downloader's update service. Authenticated non-administrative users can expl...

Jun 24, 2022
CVE-2022-29333
7.8

This vulnerability in CyberLink Power Director v14 allows attackers to execute arbitrary code with elevated privileges by tricking users into opening ...

May 24, 2022
CVE-2022-23743
7.8

CVE-2022-23743 is a local privilege escalation vulnerability in Check Point ZoneAlarm security software. It allows a local attacker to execute arbitra...

May 11, 2022
CVE-2021-39807
7.8

This vulnerability allows a user logged into the Guest account on Android devices to enable NFC functionality without proper permissions. It enables l...

Apr 12, 2022
CVE-2021-39782
7.8

This vulnerability allows local attackers to modify the PLMN SIM file without proper permission checks, potentially enabling privilege escalation on a...

Mar 30, 2022
CVE-2021-39784
7.8

CVE-2021-39784 is a local privilege escalation vulnerability in Android's CellBroadcastReceiver component. It allows attackers to enable specific cell...

Mar 30, 2022
CVE-2022-23296
7.8

This Windows Installer vulnerability allows authenticated attackers to gain SYSTEM privileges by exploiting improper handling of file operations durin...

Mar 9, 2022
CVE-2022-24408
7.8

This vulnerability allows local attackers to escalate privileges to root on affected SINUMERIK industrial control systems. The sc SUID binary contains...

Mar 8, 2022
CVE-2022-25636
7.8

CVE-2022-25636 is a heap out-of-bounds write vulnerability in the Linux kernel's netfilter component that allows local users to escalate privileges to...

Feb 24, 2022
CVE-2021-27445
7.8

Mesa Labs AmegaView versions 3.0 and prior have insecure file permissions that allow local attackers to modify critical files and escalate privileges ...

Dec 21, 2021

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 806 CVEs classified as CWE-269, with 170 rated critical and 546 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free