CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

809
Total CVEs
170
Critical
549
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 46
3 Huawei 26
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Fortinet 8
9 Apache 7
10 Citrix 7

All Improper Privilege Management CVEs (809)

CVE-2022-24408
7.8

This vulnerability allows local attackers to escalate privileges to root on affected SINUMERIK industrial control systems. The sc SUID binary contains...

Mar 8, 2022
CVE-2022-25636
7.8

CVE-2022-25636 is a heap out-of-bounds write vulnerability in the Linux kernel's netfilter component that allows local users to escalate privileges to...

Feb 24, 2022
CVE-2021-27445
7.8

Mesa Labs AmegaView versions 3.0 and prior have insecure file permissions that allow local attackers to modify critical files and escalate privileges ...

Dec 21, 2021
CVE-2021-44019
7.8

This vulnerability in Trend Micro Worry-Free Business Security allows a local attacker with low-privileged access to escalate privileges on affected s...

Dec 3, 2021
CVE-2021-44021
7.8

This is a local privilege escalation vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 that allows an attacker with low-privileged ac...

Dec 3, 2021
CVE-2021-35052
7.8

This vulnerability in Kaspersky Password Manager allows attackers to elevate process integrity levels from Medium to High, potentially gaining unautho...

Nov 23, 2021
CVE-2021-42285
7.8

CVE-2021-42285 is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to gain SYSTEM-level privileges on affecte...

Nov 10, 2021
CVE-2021-41377
7.8

This vulnerability in the Windows Fast FAT File System Driver allows attackers to escalate privileges from a low-privileged user account to SYSTEM lev...

Nov 10, 2021
CVE-2021-41370
7.8

This vulnerability allows an authenticated attacker to gain SYSTEM-level privileges on Windows systems by exploiting a flaw in NTFS file system handli...

Nov 10, 2021
CVE-2021-41367
7.8

CVE-2021-41367 is an NTFS elevation of privilege vulnerability in Windows that allows authenticated attackers to gain SYSTEM-level privileges on affec...

Nov 10, 2021
CVE-2021-36957
7.8

CVE-2021-36957 is an elevation of privilege vulnerability in Windows Desktop Bridge that allows authenticated attackers to execute arbitrary code with...

Nov 10, 2021
CVE-2019-18916
7.8

This vulnerability in HP LaserJet Solution Software allows local attackers to escalate privileges on affected systems. It affects users running vulner...

Nov 9, 2021
CVE-2021-41022
7.8

This vulnerability allows attackers to execute privileged code or commands on Windows systems running vulnerable FortiSIEM agents via PowerShell scrip...

Nov 2, 2021
CVE-2021-42104
7.8

This vulnerability allows a local attacker with low-privileged code execution on affected Trend Micro security products to escalate privileges to high...

Oct 21, 2021
CVE-2021-42106
7.8

This vulnerability allows a local attacker with low-privileged code execution on affected Trend Micro security products to escalate privileges to high...

Oct 21, 2021
CVE-2021-42108
7.8

This vulnerability allows a local attacker with low-privileged code execution on affected Trend Micro security products to escalate privileges via the...

Oct 21, 2021
CVE-2021-41347
7.8

This vulnerability allows a local attacker to elevate privileges on Windows systems by exploiting the AppX Deployment Service. It affects Windows 10, ...

Oct 13, 2021
CVE-2021-40489
7.8

CVE-2021-40489 is an elevation of privilege vulnerability in the Windows Storage Spaces Controller. It allows authenticated attackers to execute arbit...

Oct 13, 2021
CVE-2021-40478
7.8

CVE-2021-40478 is an elevation of privilege vulnerability in the Windows Storage Spaces Controller. It allows authenticated attackers to execute arbit...

Oct 13, 2021
CVE-2021-40467
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows attackers to gain SYSTEM-level privileges by exploiting improper access ...

Oct 13, 2021
CVE-2021-34411
7.8

This vulnerability allows local privilege escalation during Zoom Rooms for Windows installation. If the installer runs with elevated privileges (like ...

Sep 27, 2021
CVE-2021-36975
7.8

CVE-2021-36975 is a Win32k elevation of privilege vulnerability in Windows that allows authenticated attackers to execute arbitrary code with SYSTEM p...

Sep 15, 2021
CVE-2021-38625
7.8

This Windows kernel vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges, potentially taking full control o...

Sep 15, 2021
CVE-2021-38628
7.8

CVE-2021-38628 is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock, allowing attackers to gain SYSTEM-leve...

Sep 15, 2021
CVE-2021-38630
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a flaw in Windows Event Tracing. It...

Sep 15, 2021
CVE-2021-38633
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows attackers to gain SYSTEM-level privileges on affected systems. It affect...

Sep 15, 2021
CVE-2021-38638
7.8

This vulnerability in Windows Ancillary Function Driver for WinSock allows attackers to escalate privileges from a low-privileged user account to SYST...

Sep 15, 2021
CVE-2021-36963
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM privileges by exploiting improp...

Sep 15, 2021
CVE-2021-36973
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges on affected Windows systems. It affects Windows c...

Sep 15, 2021
CVE-2021-1853
7.8

CVE-2021-1853 is a local privilege escalation vulnerability in macOS that allows an attacker with local access to gain elevated system privileges. Thi...

Sep 8, 2021
CVE-2021-24038
7.8

This vulnerability allows an attacker to escalate privileges from an unprivileged process to a privileged one by exploiting a handle management bug in...

Aug 19, 2021
CVE-2021-34483
7.8

This vulnerability allows authenticated attackers to execute arbitrary code with SYSTEM privileges on Windows systems by exploiting the Print Spooler ...

Aug 12, 2021
CVE-2021-34537
7.8

This vulnerability allows an attacker with physical proximity to exploit a flaw in Windows Bluetooth drivers to gain SYSTEM-level privileges on affect...

Aug 12, 2021
CVE-2021-22396
7.8

This CVE describes a local privilege escalation vulnerability in specific Huawei networking products. A local attacker with standard user privileges c...

Aug 2, 2021
CVE-2021-33526
7.8

This vulnerability allows a low-privileged local attacker to execute arbitrary code with SYSTEM privileges by sending a malicious OpenVPN configuratio...

Aug 2, 2021
CVE-2021-34455
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a flaw in the Windows File History ...

Jul 16, 2021
CVE-2021-34460
7.8

CVE-2021-34460 is an elevation of privilege vulnerability in the Windows Storage Spaces Controller that allows authenticated attackers to execute arbi...

Jul 16, 2021
CVE-2021-33505
7.8

CVE-2021-33505 is a privilege escalation vulnerability in Falco where a local malicious user can bypass the detection engine by manipulating system ca...

Jul 15, 2021
CVE-2021-34514
7.8

CVE-2021-34514 is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM priv...

Jul 14, 2021
CVE-2021-25428
7.8

This vulnerability in Samsung's PackageManager allows untrusted applications to obtain dangerous permissions without user confirmation under limited c...

Jul 8, 2021
CVE-2021-35523
7.8

This vulnerability allows local unprivileged users on Windows systems to escalate privileges to SYSTEM level by modifying OpenVPN configuration files....

Jun 28, 2021
CVE-2021-27483
7.8

This vulnerability allows lower-privileged users on ZOLL Defibrillator Dashboard systems to escalate their privileges to administrative level through ...

Jun 16, 2021
CVE-2021-0052
7.8

This vulnerability in Intel's Computing Improvement Program allows authenticated local users to escalate privileges due to incorrect default permissio...

Jun 9, 2021
CVE-2021-31954
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows attackers to escalate privileges from a low-privileged user to SYSTEM le...

Jun 8, 2021
CVE-2021-22118
7.8

This vulnerability allows a locally authenticated malicious user to escalate privileges in Spring Framework WebFlux applications by manipulating tempo...

May 27, 2021
CVE-2021-22733
7.8

This vulnerability allows attackers to gain unauthorized shell access on Schneider Electric homeLYnk (Wiser For KNX) and spaceLYnk systems by loading ...

May 26, 2021
CVE-2018-16497
7.8

CVE-2018-16497 is a local privilege escalation vulnerability in Versa Analytics where cron jobs run as root but execute scripts writable by members of...

May 26, 2021
CVE-2021-20713
7.8

This is a privilege escalation vulnerability in QND Advance/Premium/Standard software versions 11.0.4i and earlier. It allows authenticated attackers ...

May 24, 2021
CVE-2021-31168
7.8

This vulnerability allows local attackers to escalate privileges on Windows systems by exploiting a flaw in the Container Manager Service. Attackers c...

May 11, 2021
CVE-2020-27518
7.8

CVE-2020-27518 is a local privilege escalation vulnerability in Windscribe VPN's WindscribeService component. Attackers with low-privilege access can ...

May 4, 2021

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 809 CVEs classified as CWE-269, with 170 rated critical and 549 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free