CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,558 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 51 of 92
- CVE-2022-21887HIGHCVSS 7.0EG 7.82022-01-11
Win32k Elevation of Privilege Vulnerability
- CVE-2022-21895HIGHCVSS 7.8EG 7.82022-01-11
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2022-21896HIGHCVSS 7.0EG 7.02022-01-11
Windows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2022-21897HIGHCVSS 7.8EG 7.82022-01-11
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-21901CRITICALCVSS 9.0EG 9.02022-01-11
Windows Hyper-V Elevation of Privilege Vulnerability
- CVE-2022-21902HIGHCVSS 7.8EG 7.82022-01-11
Windows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2022-21903HIGHCVSS 7.0EG 7.82022-01-11
Windows GDI Elevation of Privilege Vulnerability
- CVE-2022-21908HIGHCVSS 7.8EG 7.82022-01-11
Windows Installer Elevation of Privilege Vulnerability
- CVE-2022-21910HIGHCVSS 7.8EG 7.82022-01-11
Microsoft Cluster Port Driver Elevation of Privilege Vulnerability
- CVE-2022-21914HIGHCVSS 7.8EG 7.82022-01-11
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- CVE-2022-21916HIGHCVSS 7.8EG 7.82022-01-11
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-21919CRITICALCVSS 7.0EG 9.0⚠ KEV2022-01-11
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2022-21920HIGHCVSS 8.8EG 8.82022-01-11
Windows Kerberos Elevation of Privilege Vulnerability
- CVE-2022-21946HIGHCVSS 5.3EG 7.82022-03-16
A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any run…
- CVE-2022-21954MEDIUMCVSS 6.1EG 6.12022-01-11
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-21967HIGHCVSS 7.0EG 7.02022-03-09
Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
- CVE-2022-21970MEDIUMCVSS 6.1EG 6.12022-01-11
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-21981HIGHCVSS 7.8EG 7.82022-02-09
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-21989HIGHCVSS 7.8EG 7.82022-02-09
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2022-21994HIGHCVSS 7.8EG 7.82022-02-09
Windows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2022-21996HIGHCVSS 7.8EG 7.82022-02-09
Win32k Elevation of Privilege Vulnerability
- CVE-2022-21997HIGHCVSS 7.1EG 7.12022-02-09
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-21999CRITICALCVSS 7.8EG 9.0⚠ KEV2022-02-09
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-22000HIGHCVSS 7.8EG 7.82022-02-09
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-22001HIGHCVSS 7.8EG 7.82022-02-09
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- CVE-2022-22026HIGHCVSS 8.8EG 8.82022-07-12
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- CVE-2022-22031HIGHCVSS 7.8EG 7.82022-07-12
Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability
- CVE-2022-22034HIGHCVSS 7.8EG 7.82022-07-12
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2022-22036HIGHCVSS 7.0EG 7.02022-07-12
Performance Counters for Windows Elevation of Privilege Vulnerability
- CVE-2022-22037HIGHCVSS 7.5EG 7.52022-07-12
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-22041MEDIUMCVSS 6.8EG 6.82022-07-12
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-22043HIGHCVSS 7.8EG 7.82022-07-12
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
- CVE-2022-22045HIGHCVSS 7.8EG 7.82022-07-12
Windows.Devices.Picker.dll Elevation of Privilege Vulnerability
- CVE-2022-22047CRITICALCVSS 7.8EG 9.0⚠ KEV2022-07-12
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- CVE-2022-22141HIGHCVSS 7.8EG 7.82022-03-11
'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 t…
- CVE-2022-22187HIGHCVSS 7.8EG 7.82022-04-14
An Improper Privilege Management vulnerability in the Windows Installer framework used in the Juniper Networks Juniper Identity Management Service (JIMS) allows an unprivileged user to trigger a repair operation. Running a repair operation…
- CVE-2022-22239HIGHCVSS 8.2EG 8.22022-10-18
An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges to escalate their privileges on the device and potentially r…
- CVE-2022-22257HIGHCVSS 7.5EG 7.52022-04-11
The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.
- CVE-2022-22263MEDIUMCVSS 4.0EG 4.02022-01-10
Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.
- CVE-2022-22266MEDIUMCVSS 4.0EG 4.02022-01-10
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
- CVE-2022-22315HIGHCVSS 8.8EG 8.82022-04-27
IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955.
- CVE-2022-22328MEDIUMCVSS 6.2EG 6.22022-04-01
IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data. IBM X-Force ID: 218871.
- CVE-2022-22390HIGHCVSS 7.5EG 7.52022-06-24
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.
- CVE-2022-22394HIGHCVSS 8.8EG 8.82022-03-21
The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and…
- CVE-2022-22441MEDIUMCVSS 6.5EG 6.52022-04-28
IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege escalation vulnerability. IBM X-Force ID: 224426.
- CVE-2022-22483MEDIUMCVSS 6.5EG 6.52022-09-13
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM…
- CVE-2022-2249HIGHCVSS 7.7EG 7.72022-10-12
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.…
- CVE-2022-22509HIGHCVSS 8.8EG 8.82022-02-02
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
- CVE-2022-22521HIGHCVSS 7.3EG 7.32022-04-27
In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to…
- CVE-2022-22572HIGHCVSS 8.8EG 8.82022-04-11
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →