Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-02-20 CVE-2022-25372 Improper Privilege Management vulnerability in Pritunl Pritunl-Client-Electron
Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.
local
low complexity
pritunl CWE-269
7.8
2022-02-14 CVE-2022-25150 Improper Privilege Management vulnerability in Malwarebytes Binisoft Windows Firewall Control
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.
local
low complexity
malwarebytes CWE-269
7.8
2022-02-11 CVE-2021-22801 Improper Privilege Management vulnerability in Schneider-Electric Connexium Network Manager
A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with specially crafted event actions.
network
low complexity
schneider-electric CWE-269
critical
9.8
2022-02-11 CVE-2022-24927 Improper Privilege Management vulnerability in Samsung Video Player
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.
network
low complexity
samsung CWE-269
critical
9.8
2022-02-09 CVE-2021-36302 Improper Privilege Management vulnerability in Dell EMC Integrated System for Microsoft Azure Stack HUB Firmware
All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability.
network
low complexity
dell CWE-269
critical
9.9
2022-02-09 CVE-2021-37852 Improper Privilege Management vulnerability in Eset products
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
local
low complexity
eset CWE-269
7.8
2022-02-02 CVE-2022-22509 Improper Privilege Management vulnerability in Phoenixcontact products
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
network
low complexity
phoenixcontact CWE-269
8.8
2022-01-24 CVE-2021-45222 Improper Privilege Management vulnerability in Coins-Global Coins Construction Cloud 11.12
An issue was discovered in COINS Construction Cloud 11.12.
network
low complexity
coins-global CWE-269
8.8
2022-01-18 CVE-2022-0090 Improper Privilege Management vulnerability in Gitlab
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1.
network
low complexity
gitlab CWE-269
6.5
2022-01-13 CVE-2021-34998 Improper Privilege Management vulnerability in Watchguard Panda Antivirus 18.0
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0.
local
low complexity
watchguard CWE-269
7.8