Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2023-01-18 CVE-2023-22809 Improper Privilege Management vulnerability in multiple products
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process.
7.8
2023-01-13 CVE-2023-0221 Improper Privilege Management vulnerability in Mcafee Application and Change Control
Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.
local
low complexity
mcafee CWE-269
4.4
2023-01-10 CVE-2023-21531 Improper Privilege Management vulnerability in Microsoft Azure Service Fabric 8.2/9.0/9.1
Azure Service Fabric Container Elevation of Privilege Vulnerability
local
high complexity
microsoft CWE-269
7.0
2023-01-10 CVE-2023-21542 Improper Privilege Management vulnerability in Microsoft products
Windows Installer Elevation of Privilege Vulnerability
local
high complexity
microsoft CWE-269
7.0
2023-01-10 CVE-2023-21549 Improper Privilege Management vulnerability in Microsoft products
Windows SMB Witness Service Elevation of Privilege Vulnerability
network
low complexity
microsoft CWE-269
8.8
2023-01-10 CVE-2023-21551 Improper Privilege Management vulnerability in Microsoft products
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2023-01-10 CVE-2023-21552 Improper Privilege Management vulnerability in Microsoft products
Windows GDI Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2023-01-10 CVE-2023-21561 Improper Privilege Management vulnerability in Microsoft products
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2023-01-10 CVE-2023-21730 Improper Privilege Management vulnerability in Microsoft products
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2023-01-10 CVE-2023-21755 Improper Privilege Management vulnerability in Microsoft products
Windows Kernel Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8