CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

802
Total CVEs
166
Critical
546
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 46
3 Huawei 26
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Fortinet 8
9 Apache 7
10 Citrix 7

All Improper Privilege Management CVEs (802)

CVE-2025-66374
7.8

This vulnerability in CyberArk Endpoint Privilege Manager Agent allows a local user to escalate privileges by exploiting policy elevation of an Admini...

Feb 3, 2026
CVE-2025-37186
7.8

A local privilege escalation vulnerability in HPE Aruba Networking VIA client allows authenticated local users to execute arbitrary code with root pri...

Jan 13, 2026
CVE-2025-67792
7.8

A local privilege escalation vulnerability in DriveLock allows unprivileged Windows users to manipulate DriveLock processes and execute arbitrary comm...

Dec 17, 2025
CVE-2025-14252
7.8

An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers with local access to read/write arbitrary memory, I/O po...

Dec 16, 2025
CVE-2025-43512
7.8

A privilege escalation vulnerability in Apple operating systems allows malicious applications to gain elevated privileges. This affects macOS, iOS, an...

Dec 12, 2025
CVE-2025-43320
7.8

This macOS vulnerability allows malicious applications to bypass launch constraint protections and execute code with elevated privileges. It affects m...

Dec 12, 2025
CVE-2025-12381
7.8

A local privilege escalation vulnerability in AlgoSec Firewall Analyzer allows authenticated users with command-line access to abuse sudoers file perm...

Dec 9, 2025
CVE-2025-59514
7.8

This vulnerability in Microsoft Streaming Service allows an authenticated attacker to escalate privileges on a local system. Attackers with standard u...

Nov 11, 2025
CVE-2025-64507
7.8

This vulnerability in Incus allows unprivileged users with container root access and host access to escalate privileges to root on the host system. It...

Nov 10, 2025
CVE-2025-48982
7.8

This vulnerability in Veeam Agent for Microsoft Windows allows local attackers to escalate privileges to SYSTEM level by tricking an administrator int...

Oct 31, 2025
CVE-2025-9068
7.8

This vulnerability allows authenticated Windows users to hijack a repair process in Rockwell Automation's FTLinx software, gaining SYSTEM-level comman...

Oct 14, 2025
CVE-2025-9067
7.8

This vulnerability allows authenticated Windows users to hijack the repair process of FTLinx's Microsoft Installer File (MSI), gaining a SYSTEM-level ...

Oct 14, 2025
CVE-2025-43333
7.8

A permissions vulnerability in macOS allows applications to escalate privileges to root level. This affects macOS systems running versions prior to Ta...

Sep 15, 2025
CVE-2025-26435
7.8

This vulnerability allows a secondary user on an Android device to disable the primary user's deceptive app scanning setting due to a logic error in t...

Sep 4, 2025
CVE-2025-43256
7.8

This vulnerability allows an application to gain root privileges on affected macOS systems through improper state management. It affects macOS Sequoia...

Jul 30, 2025
CVE-2025-43248
7.8

This CVE describes a privilege escalation vulnerability in macOS where a malicious application could exploit a logic flaw to gain root privileges. It ...

Jul 30, 2025
CVE-2025-43019
7.8

CVE-2025-43019 is a local privilege escalation vulnerability in HP Support Assistant that allows authenticated attackers to delete arbitrary files, po...

Jul 8, 2025
CVE-2025-0320
7.8

CVE-2025-0320 is a local privilege escalation vulnerability in Citrix Secure Access Client for Windows that allows authenticated low-privileged users ...

Jun 17, 2025
CVE-2025-5687
7.8

A privilege escalation vulnerability in Mozilla VPN on macOS allows a local user to gain root privileges. This affects macOS users running Mozilla VPN...

Jun 11, 2025
CVE-2025-47955
7.8

This vulnerability in Windows Remote Access Connection Manager allows authenticated attackers to escalate privileges on a local system. Attackers with...

Jun 10, 2025
CVE-2025-27811
7.8

This vulnerability allows a local attacker with limited privileges to escalate to SYSTEM-level privileges through a vulnerable COM interface in Razer ...

Jun 4, 2025
CVE-2025-4636
7.8

CVE-2025-4636 is a privilege escalation vulnerability in the airpointer web platform where the web user has excessive privileges. An attacker who comp...

May 30, 2025
CVE-2024-40462
7.8

A local privilege escalation vulnerability in Ocuco Innovation v.2.10.24.51 allows attackers with local access to gain elevated privileges through the...

May 22, 2025
CVE-2024-40460
7.8

A local privilege escalation vulnerability in Ocuco Innovation v.2.10.24.51 allows attackers to gain elevated system privileges by exploiting the JOBE...

May 22, 2025
CVE-2025-24258
7.8

This CVE describes a permissions escalation vulnerability in macOS that allows an application to gain root privileges. It affects macOS Ventura, Sonom...

May 12, 2025
CVE-2025-25230
7.8

CVE-2025-25230 is a local privilege escalation vulnerability in Omnissa Horizon Client for Windows. An attacker with local access to a system where th...

Apr 16, 2025
CVE-2025-29800
7.8

CVE-2025-29800 is a local privilege escalation vulnerability in Microsoft AutoUpdate (MAU) that allows authenticated attackers to gain elevated system...

Apr 8, 2025
CVE-2025-22231
7.8

CVE-2025-22231 is a local privilege escalation vulnerability in VMware Aria Operations. An attacker with local administrative access can elevate privi...

Apr 1, 2025
CVE-2025-27644
7.8

This CVE describes a local privilege escalation vulnerability in Vasion Print (formerly PrinterLogic) that allows authenticated local users to gain el...

Mar 5, 2025
CVE-2025-0893
7.8

This vulnerability allows local attackers to escalate privileges on systems running vulnerable versions of Symantec Diagnostic Tool (SymDiag). Attacke...

Feb 19, 2025
CVE-2025-0327
7.8

This CVE describes an Improper Privilege Management vulnerability in two Schneider Electric services where an attacker with standard user privileges c...

Feb 13, 2025
CVE-2024-11467
7.8

CVE-2024-11467 is a local privilege escalation vulnerability in Omnissa Horizon Client for macOS that allows authenticated users to gain root privileg...

Feb 4, 2025
CVE-2025-0834
7.8

A privilege escalation vulnerability in Wondershare Dr.Fone version 13.5.21 allows attackers to replace the ElevationService.exe binary with malicious...

Jan 30, 2025
CVE-2024-49742
7.8

This vulnerability allows a malicious app to hide its notification access permission in Android Settings, preventing users from revoking it. Attackers...

Jan 21, 2025
CVE-2018-9375
7.8

CVE-2018-9375 is a confused deputy vulnerability in Android's UserDictionaryProvider that allows malicious apps to add or delete words from the user d...

Jan 17, 2025
CVE-2025-21360
7.8

This vulnerability in Microsoft AutoUpdate allows local attackers to escalate privileges on affected macOS systems. An authenticated attacker could ex...

Jan 14, 2025
CVE-2025-21287
7.8

This Windows Installer vulnerability allows authenticated attackers to elevate privileges on affected systems. Attackers could gain SYSTEM-level acces...

Jan 14, 2025
CVE-2024-11128
7.8

This vulnerability allows attackers to inject malicious dynamic libraries into Bitdefender Virus Scanner on macOS, bypassing Apple's security protecti...

Jan 13, 2025
CVE-2024-53706
7.8

This vulnerability in SonicOS Cloud NSv allows authenticated low-privileged users to escalate privileges to root, potentially leading to full system c...

Jan 9, 2025
CVE-2024-56447
7.8

This vulnerability involves improper permission control in the window management module, allowing unauthorized access to sensitive information. It aff...

Jan 8, 2025
CVE-2024-55631
7.8

This is a local privilege escalation vulnerability in Trend Micro Apex One security software. An attacker with existing low-privileged access on a sys...

Dec 31, 2024
CVE-2020-9080
7.8

This is a local privilege escalation vulnerability in Huawei smartphones that allows authenticated local attackers to gain elevated privileges. Attack...

Dec 27, 2024
CVE-2024-52336
7.8

This CVE describes a local privilege escalation vulnerability in the Tuned package. A local non-privileged user can exploit the unauthenticated D-Bus ...

Nov 26, 2024
CVE-2024-38830
7.8

CVE-2024-38830 is a local privilege escalation vulnerability in VMware Aria Operations. Attackers with local administrative access can exploit this to...

Nov 26, 2024
CVE-2024-48903
7.8

An improper access control vulnerability in Trend Micro Deep Security Agent 20 allows local attackers to escalate privileges on affected systems. Atta...

Oct 22, 2024
CVE-2024-40861
7.8

This vulnerability in macOS allows malicious applications to escalate privileges and gain root access. It affects macOS systems before Sequoia 15. Any...

Sep 17, 2024
CVE-2024-29779
7.8

CVE-2024-29779 is a local privilege escalation vulnerability in Android that allows attackers to gain root privileges without requiring user interacti...

Sep 13, 2024
CVE-2024-5760
7.8

The Samsung Universal Print Driver for Windows contains a privilege escalation vulnerability that allows attackers to create a reverse shell with elev...

Sep 11, 2024
CVE-2024-8306
7.8

This CVE describes an improper privilege management vulnerability in Schneider Electric software that allows authenticated non-admin users to escalate...

Sep 11, 2024
CVE-2024-40657
7.8

This vulnerability in Android's Settings app allows a malicious app to disable other users' apps on multi-user devices through a confused deputy attac...

Sep 11, 2024

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 802 CVEs classified as CWE-269, with 166 rated critical and 546 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free