CWE-379: CWE-379

17
Total CVEs
0
Critical
13
High
7.2
Avg CVSS

Yearly Trend

2026
2
2025
5
2024
3
2023
4
2021
3

Top Affected Vendors

1 Adobe 6
2 Microsoft 1
3 Ibm 1
4 Redhat 1
5 Autodesk 1
6 Zoom 1
7 Forescout 1
8 Lakesidesoftware 1
9 Pyinstaller 1
10 Atera 1

All CWE-379 CVEs (17)

CVE-2023-49797
8.8

This vulnerability allows an unprivileged attacker to trick a PyInstaller-built application running with elevated privileges into deleting arbitrary f...

Dec 9, 2023
CVE-2024-9950
7.8

An unauthenticated attacker can modify compliance scripts in Forescout SecureConnector v11.3.07.0109 on Windows due to insecure temporary directory pe...

Jan 2, 2025
CVE-2024-9500
7.8

This vulnerability allows attackers to escalate privileges to SYSTEM level by placing a malicious DLL in temporary directories used by Autodesk Instal...

Nov 15, 2024
CVE-2023-6080
7.8

This vulnerability in Lakeside Software's SysTrack LsiAgent Installer allows local attackers to escalate privileges to SYSTEM level access on Windows ...

Oct 18, 2024
CVE-2023-3972
7.8

This vulnerability allows unprivileged local users to escalate privileges to root by exploiting insecure temporary directory handling in insights-clie...

Nov 1, 2023
CVE-2023-37243
7.8

This vulnerability allows standard users to achieve privilege escalation to SYSTEM level through DLL hijacking. When the system reboots, a vulnerable ...

Oct 31, 2023
CVE-2023-26396
7.8

This vulnerability in Adobe Acrobat Reader allows attackers to create temporary files with incorrect permissions, potentially leading to privilege esc...

Apr 12, 2023
CVE-2021-21100
7.8

Adobe Digital Editions versions 4.5.11.187245 and earlier contain a privilege escalation vulnerability during installation that allows an unauthentica...

Apr 15, 2021
CVE-2021-28613
7.4

This vulnerability in Adobe Creative Cloud Desktop Application allows an attacker with local access, administrator privileges, and user interaction to...

Sep 27, 2021
CVE-2025-21173
7.3

This CVE describes a privilege escalation vulnerability in .NET that allows authenticated attackers to elevate their privileges on affected systems. I...

Jan 14, 2025
CVE-2021-40708
7.3

This vulnerability in Adobe Genuine Service allows authenticated attackers to escalate privileges through the AGSService installer. Attackers can gain...

Sep 29, 2021
CVE-2024-24693
7.2

An improper access control vulnerability in the Zoom Rooms Client for Windows installer allows authenticated local users to cause denial of service. T...

Mar 13, 2024
CVE-2025-10279
7.0

This CVE describes a local privilege escalation vulnerability in mlflow versions before 3.4.0 where temporary directories for Python virtual environme...

Feb 2, 2026
CVE-2025-71176
6.8

This vulnerability in pytest allows local users on UNIX systems to cause denial of service or potentially escalate privileges by exploiting predictabl...

Jan 22, 2026
CVE-2025-64896
5.5

Creative Cloud Desktop versions 6.4.0.361 and earlier contain a vulnerability where temporary files are created with incorrect permissions. An attacke...

Dec 9, 2025
CVE-2025-21162
5.5

Photoshop Elements 2025.0 and earlier versions contain a vulnerability where temporary files are created with insecure permissions, allowing local pri...

Feb 11, 2025
CVE-2025-33111
4.3

This vulnerability in IBM Controller and Cognos Controller allows authenticated attackers to potentially access sensitive information through race con...

Dec 8, 2025

About CWE-379 (CWE-379)

Our database tracks 17 CVEs classified as CWE-379, with 0 rated critical and 13 rated high severity. The average CVSS score for CWE-379 vulnerabilities is 7.2.

External reference: View CWE-379 on MITRE CWE →

Monitor CWE-379 Vulnerabilities

Get alerted when new CWE-379 CVEs affect your infrastructure.

Start Monitoring Free