Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-12-03 CVE-2021-44021 Improper Privilege Management vulnerability in Trendmicro Worry-Free Business Security 10.0
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations.
local
low complexity
trendmicro CWE-269
7.2
2021-11-24 CVE-2021-43211 Improper Privilege Management vulnerability in Microsoft Windows 10 Update Assistant
Windows 10 Update Assistant Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
5.5
2021-11-23 CVE-2021-35052 Improper Privilege Management vulnerability in Kaspersky Password Manager 9.0.2
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
local
low complexity
kaspersky CWE-269
4.6
2021-11-21 CVE-2021-28710 Improper Privilege Management vulnerability in multiple products
certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-level translation (EPT), and IOMMUs.
local
low complexity
xen fedoraproject CWE-269
8.8
2021-11-20 CVE-2021-36307 Improper Privilege Management vulnerability in Dell Networking Os10
Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability.
network
dell CWE-269
8.5
2021-11-18 CVE-2021-23193 Improper Privilege Management vulnerability in Gallagher Command Centre
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server.
network
low complexity
gallagher CWE-269
4.0
2021-11-18 CVE-2021-35534 Improper Privilege Management vulnerability in Hitachi products
Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to an internal database tables, could allow anybody with user credentials to bypass security controls that is enforced by the product.
network
low complexity
hitachi CWE-269
7.2
2021-11-18 CVE-2021-0655 Improper Privilege Management vulnerability in Google Android 10.0/11.0
In mdlactl driver, there is a possible memory corruption due to an incorrect bounds check.
local
low complexity
google CWE-269
4.6
2021-11-17 CVE-2021-33089 Improper Privilege Management vulnerability in Intel NUC Hdmi Firmware Update Tool 1.78.2.0.7
Improper access control in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC8i3BE, NUC8i5BE, NUC8i7BE before version 1.78.4.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-269
4.6
2021-11-17 CVE-2021-42956 Improper Privilege Management vulnerability in Zoho Manageengine Remote Access Plus Server
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability.
network
low complexity
zoho CWE-269
6.5