Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-04-15 CVE-2020-8948 Improper Privilege Management vulnerability in Sierrawireless Mobile Broadband Driver Package
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links.
local
low complexity
sierrawireless CWE-269
7.2
2020-04-15 CVE-2020-1094 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-04-15 CVE-2020-1029 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-04-15 CVE-2020-1019 Improper Privilege Management vulnerability in Microsoft RMS Sharing
An elevation of privilege vulnerability exists in RMS Sharing App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft RMS Sharing App for Mac Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-04-15 CVE-2020-1017 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way the Windows Push Notification Service handles objects in memory, aka 'Windows Push Notification Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-04-15 CVE-2020-1015 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the User-Mode Power Service (UMPS) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-04-15 CVE-2020-1014 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-04-15 CVE-2020-1011 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows System Assessment Tool improperly handles file operations, aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-04-15 CVE-2020-1009 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Microsoft Store Install Service handles file operations in protected locations, aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-04-15 CVE-2020-1006 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way the Windows Push Notification Service handles objects in memory, aka 'Windows Push Notification Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2