Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2023-07-14 CVE-2023-3513 Improper Privilege Management vulnerability in Razer Central
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and triggering an insecure .NET deserialization.
local
low complexity
razer CWE-269
7.8
2023-07-14 CVE-2023-3514 Improper Privilege Management vulnerability in Razer Central
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and calling "AddModule" or "UninstallModules" command to execute arbitrary executable file.
local
low complexity
razer CWE-269
7.8
2023-07-10 CVE-2023-30765 Improper Privilege Management vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A/1.0.5
?Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.
network
low complexity
deltaww CWE-269
critical
9.8
2023-07-10 CVE-2021-42082 Improper Privilege Management vulnerability in Osnexus Quantastor 4.3.0
Local users are able to execute scripts under root privileges.
local
low complexity
osnexus CWE-269
7.8
2023-07-10 CVE-2023-27558 Improper Privilege Management vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path.
local
low complexity
ibm CWE-269
7.8
2023-07-10 CVE-2023-29256 Improper Privilege Management vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege management when certain federation features are used.
network
low complexity
ibm CWE-269
6.5
2023-07-06 CVE-2023-30642 Improper Privilege Management vulnerability in Samsung Android 12.0/13.0
Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.
local
low complexity
samsung CWE-269
5.5
2023-07-04 CVE-2023-25521 Improper Privilege Management vulnerability in Nvidia DGX A100 Firmware and DGX A800 Firmware
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whereby proper input parameter validation is not performed.
local
low complexity
nvidia CWE-269
7.8
2023-06-28 CVE-2023-20136 Improper Privilege Management vulnerability in Cisco Secure Workload
A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges.
network
low complexity
cisco CWE-269
6.5
2023-06-26 CVE-2023-34146 Improper Privilege Management vulnerability in Trendmicro Apex ONE
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is a similar, but not identical vulnerability as CVE-2023-34147 and CVE-2023-34148.
local
low complexity
trendmicro CWE-269
7.8