CWE-276: CWE-276
Yearly Trend
Top Affected Vendors
All CWE-276 CVEs (433)
This is a privilege escalation vulnerability in Apple operating systems that allows a local user to gain elevated privileges. It affects iOS, iPadOS, ...
Jul 27, 2023The Atera Agent on Windows creates temporary files in directories with insecure permissions, allowing local attackers to write arbitrary files. This a...
Jul 24, 2023This vulnerability allows users with hacluster group access on openSUSE Tumbleweed systems to escalate privileges to root due to incorrect default per...
Jul 7, 2023This vulnerability allows an attacker to bypass the Android Setup Wizard through a logic error in USB accessory handling, potentially gaining elevated...
Jun 28, 2023This vulnerability allows a low-privileged local attacker on Windows systems with Cisco AnyConnect or Secure Client to elevate privileges to SYSTEM le...
Jun 28, 2023This CVE describes a privilege escalation vulnerability in macOS where a malicious application could exploit a logic flaw to gain root privileges. It ...
Jun 23, 2023This CVE describes a privilege escalation vulnerability in iTunes for Windows where a malicious application could exploit a logic flaw to gain elevate...
Jun 23, 2023This vulnerability affects HPE MC990 X and UV300 RMC components with inadequate default configurations, allowing attackers to escalate privileges on a...
Jun 16, 2023This Android vulnerability allows malicious apps to launch activities while in the background, bypassing normal restrictions. It enables local privile...
Jun 15, 2023This vulnerability allows unprivileged local users to escalate their privileges to SYSTEM level on Windows systems. It affects Foxit PDF Reader and Ed...
May 19, 2023This vulnerability allows low-privileged Sage 300 workstation users to access and modify credentials stored in the SharedData folder on connected serv...
Apr 28, 2023CVE-2021-41614 is a privilege escalation vulnerability in the OpenRISC mor1kx processor controller unit where user programs from unauthorized privileg...
Apr 18, 2023This vulnerability allows a local attacker with shell access and low privileges to modify system files or execute commands as root due to improper fil...
Apr 17, 2023Dell PowerScale OneFS versions 8.2.x through 9.5.0.x contain a local privilege escalation vulnerability. A low-privileged local attacker could exploit...
Apr 4, 2023This vulnerability allows local attackers with access to the _rmt user account to escalate privileges to root due to incorrect default permissions in ...
Feb 7, 2023CVE-2022-23454 is a set of vulnerabilities in HP Support Assistant that could allow attackers to escalate privileges, compromise system integrity, com...
Feb 1, 2023This vulnerability allows malicious apps to execute code with shell user privileges when wireless debugging is enabled on Android devices, due to a mi...
Apr 12, 2022CVE-2021-39780 allows attackers to bypass developer settings requirements for capturing system traces in Android 12L due to a missing permission check...
Mar 30, 2022This vulnerability allows local attackers to bypass Bluetooth permission checks on Android devices, potentially gaining elevated privileges without us...
Mar 30, 2022This vulnerability in Intel Quartus Prime Pro Edition allows authenticated local users to escalate privileges due to improper file permissions. Attack...
Feb 9, 2022This vulnerability in Intel Advisor installer versions before 2021.4.0 sets incorrect default file permissions during installation, allowing authentic...
Feb 9, 2022This vulnerability allows local attackers to escalate privileges by exploiting incorrect default permissions on the base installation directory. It af...
Feb 9, 2022This vulnerability allows local attackers to escalate privileges to SYSTEM authority on Windows systems running Advantech R-SeeNet 2.4.15 by replacing...
Dec 22, 2021This vulnerability in the Automox Agent on Windows allows local privilege escalation due to incorrect permissions on a temporary directory. An attacke...
Dec 15, 2021CVE-2021-42711 is a local privilege escalation vulnerability in Barracuda Network Access Client where an unprivileged user can create a temporary file...
Dec 1, 2021This vulnerability allows authenticated local users to escalate privileges due to incorrect default permissions in Intel VTune Profiler installer. It ...
Nov 17, 2021This vulnerability allows authenticated local users to escalate privileges due to incorrect default permissions in the Intel oneAPI Rendering Toolkit ...
Nov 17, 2021This vulnerability in Intel Thunderbolt non-DCH driver installer for Windows allows authenticated local users to escalate privileges due to improper p...
Nov 17, 2021This vulnerability allows authenticated local users to escalate privileges on Intel NUC M15 Laptop Kit systems due to incorrect default permissions in...
Nov 17, 2021This vulnerability allows authenticated local users to escalate privileges on affected Intel NUC systems due to incorrect default permissions in the H...
Nov 17, 2021This vulnerability allows authenticated local users to escalate privileges on Intel NUC M15 Laptop Kit systems due to incorrect default permissions in...
Nov 17, 2021This vulnerability allows a local attacker to escalate privileges to SYSTEM level on Windows systems by exploiting incorrect default permissions in Bi...
Oct 28, 2021A permission issue in the Cohesity Linux agent allows local privilege escalation. An underprivileged Linux user can gain additional privileges if cert...
Aug 6, 2021This vulnerability allows local privilege escalation in Trend Micro security products. An attacker with low-privileged code execution can modify scrip...
Aug 4, 2021This vulnerability in Intel Optane DC Persistent Memory for Windows software allows authenticated local users to escalate privileges due to incorrect ...
Jun 9, 2021This CVE describes a local privilege escalation vulnerability in the Guild Wars 2 game launcher where an authenticated user can replace the executable...
Jun 9, 2021CVE-2021-27032 is a privilege escalation vulnerability in Autodesk Licensing Installer where weak service permissions allow any local user to modify s...
May 28, 2021This vulnerability allows local attackers in the vboxusers group on openSUSE systems to escalate privileges to root due to incorrect default permissio...
May 5, 2021This vulnerability in IBM Spectrum Protect Client allows a local user to escalate privileges to SYSTEM/root level due to insecure directory permission...
Apr 26, 2021This CVE describes a local privilege escalation vulnerability in Dream Report 5 R20-2 where attackers can replace the Syncfusion Dashboard Service bin...
Apr 9, 2021This CVE describes a privilege escalation vulnerability in Dream Report 5 R20-2 where weak permissions on COM Class Identifiers allow attackers to exe...
Apr 9, 2021This vulnerability allows local attackers to escalate privileges to NT SYSTEM level by exploiting insecure file permissions in Advantech WebAccess/SCA...
Mar 3, 2021This vulnerability allows local attackers to escalate privileges on systems running Sytech XL Reporter v14.0.1 by exploiting weak file system permissi...
Feb 19, 2021This vulnerability allows local attackers to escalate privileges on systems running vulnerable versions of Atlassian Bitbucket Server and Data Center ...
Feb 18, 2021This vulnerability allows local attackers to escalate privileges on systems running Win-911 Enterprise V4.20.13 by exploiting weak file system permiss...
Jan 5, 2021A local privilege escalation vulnerability in Windows software allows low-privileged users to corrupt sensitive data. The vulnerability exists because...
Sep 18, 2025Faronics WINSelect stores its encrypted configuration file with overly permissive 'Everyone' read/write permissions, allowing any local user to modify...
Jun 24, 2024This CVE describes a local privilege escalation vulnerability in Toshiba printers that allows attackers to replace legitimate programs with malicious ...
Jun 14, 2024This vulnerability in ZTE AndroidTV set-top boxes allows non-privileged applications to bypass permission controls and execute protected functions. At...
Jun 16, 2023Keyfactor Command versions before 12.5.0 have an incorrect access control vulnerability where access tokens are over-permissioned, allowing users to p...
Dec 18, 2024About CWE-276 (CWE-276)
Our database tracks 433 CVEs classified as CWE-276, with 59 rated critical and 280 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.
External reference: View CWE-276 on MITRE CWE →
Monitor CWE-276 Vulnerabilities
Get alerted when new CWE-276 CVEs affect your infrastructure.
Start Monitoring Free