CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,489 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 25 of 90
- CVE-2020-16935HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.</p> <p>To exploit this vulne…
- CVE-2020-16936HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker co…
- CVE-2020-16939HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an att…
- CVE-2020-16940HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated c…
- CVE-2020-16958HIGHCVSS 7.8EG 7.82020-12-10
Windows Backup Engine Elevation of Privilege Vulnerability
- CVE-2020-16959HIGHCVSS 7.8EG 7.82020-12-10
Windows Backup Engine Elevation of Privilege Vulnerability
- CVE-2020-16960HIGHCVSS 7.8EG 7.82020-12-10
Windows Backup Engine Elevation of Privilege Vulnerability
- CVE-2020-16961HIGHCVSS 7.8EG 7.82020-12-10
Windows Backup Engine Elevation of Privilege Vulnerability
- CVE-2020-16962HIGHCVSS 7.8EG 7.82020-12-10
Windows Backup Engine Elevation of Privilege Vulnerability
- CVE-2020-16963HIGHCVSS 7.8EG 7.82020-12-10
Windows Backup Engine Elevation of Privilege Vulnerability
- CVE-2020-16964HIGHCVSS 7.8EG 7.82020-12-10
Windows Backup Engine Elevation of Privilege Vulnerability
- CVE-2020-16972HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker co…
- CVE-2020-16973HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker co…
- CVE-2020-16974HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker co…
- CVE-2020-16975HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker co…
- CVE-2020-16976HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker co…
- CVE-2020-16980HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vul…
- CVE-2020-16981MEDIUMCVSS 6.1EG 6.12020-11-11
Azure Sphere Elevation of Privilege Vulnerability
- CVE-2020-16988MEDIUMCVSS 6.9EG 6.92020-11-11
Azure Sphere Elevation of Privilege Vulnerability
- CVE-2020-16989MEDIUMCVSS 5.4EG 5.42020-11-11
Azure Sphere Elevation of Privilege Vulnerability
- CVE-2020-16992HIGHCVSS 7.5EG 7.52020-11-11
Azure Sphere Elevation of Privilege Vulnerability
- CVE-2020-16993MEDIUMCVSS 5.4EG 5.42020-11-11
Azure Sphere Elevation of Privilege Vulnerability
- CVE-2020-16995HIGHCVSS 7.8EG 7.82020-10-16
<p>An elevation of privilege vulnerability exists in Network Watcher Agent virtual machine extension for Linux. An attacker who successfully exploited this vulnerability could execute code with elevated privileges.</p> <p>To exploit this v…
- CVE-2020-16998HIGHCVSS 7.0EG 7.02020-11-11
DirectX Elevation of Privilege Vulnerability
- CVE-2020-17001HIGHCVSS 7.8EG 7.82020-11-11
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2020-17007HIGHCVSS 7.0EG 7.02020-11-11
Windows Error Reporting Elevation of Privilege Vulnerability
- CVE-2020-17010HIGHCVSS 7.8EG 7.82020-11-11
Win32k Elevation of Privilege Vulnerability
- CVE-2020-17011HIGHCVSS 7.8EG 7.82020-11-11
Windows Port Class Library Elevation of Privilege Vulnerability
- CVE-2020-17012HIGHCVSS 7.8EG 7.82020-11-11
Windows Bind Filter Driver Elevation of Privilege Vulnerability
- CVE-2020-17014HIGHCVSS 7.8EG 7.82020-11-11
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2020-17024HIGHCVSS 7.8EG 7.82020-11-11
Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability
- CVE-2020-17025HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17026HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17027HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17028HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17031HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17032HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17033HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17034HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17035HIGHCVSS 7.8EG 7.82020-11-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2020-17037HIGHCVSS 7.8EG 7.82020-11-11
Windows WalletService Elevation of Privilege Vulnerability
- CVE-2020-17038HIGHCVSS 7.8EG 7.82020-11-11
Win32k Elevation of Privilege Vulnerability
- CVE-2020-17041HIGHCVSS 7.8EG 7.82020-11-11
Windows Print Configuration Elevation of Privilege Vulnerability
- CVE-2020-17043HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17044HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17049MEDIUMCVSS 6.6EG 7.22020-11-11
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised servic…
- CVE-2020-17055HIGHCVSS 7.8EG 7.82020-11-11
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2020-17057HIGHCVSS 7.0EG 7.02020-11-11
Windows Win32k Elevation of Privilege Vulnerability
- CVE-2020-17070HIGHCVSS 7.8EG 7.82020-11-11
Windows Update Medic Service Elevation of Privilege Vulnerability
- CVE-2020-17073HIGHCVSS 7.8EG 7.82020-11-11
Windows Update Orchestrator Service Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →