Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-06-09 CVE-2020-1170 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-06-09 CVE-2020-1163 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-06-09 CVE-2020-1162 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-06-09 CVE-2020-0916 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-06-09 CVE-2020-0915 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-06-07 CVE-2020-13912 Improper Privilege Management vulnerability in Solarwinds Advanced Monitoring Agent 10.8.8
SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to a certain .exe file.
6.0
2020-06-05 CVE-2020-13841 Improper Privilege Management vulnerability in Google Android 10.0/9.0
An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets).
network
low complexity
google CWE-269
critical
10.0
2020-06-04 CVE-2020-11679 Improper Privilege Management vulnerability in Castel Nextgen DVR Firmware 1.0.0
Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality.
network
low complexity
castel CWE-269
6.5
2020-06-03 CVE-2020-7014 Improper Privilege Management vulnerability in Elastic Elasticsearch
The fix for CVE-2020-7009 was found to be incomplete.
network
low complexity
elastic CWE-269
6.5
2020-06-03 CVE-2020-4307 Improper Privilege Management vulnerability in IBM Security Guardium 11.1
IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of service attack.
low complexity
ibm CWE-269
3.3