Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-06-30 CVE-2021-22326 Improper Privilege Management vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability.
local
low complexity
huawei CWE-269
7.1
2021-06-30 CVE-2021-22376 Improper Privilege Management vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a Improper Privilege Management vulnerability.
local
low complexity
huawei CWE-269
8.4
2021-06-30 CVE-2021-28692 Improper Privilege Management vulnerability in XEN
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands.
local
low complexity
xen CWE-269
7.1
2021-06-28 CVE-2021-35523 Improper Privilege Management vulnerability in Securepoint Openvpn-Client
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM.
local
low complexity
securepoint CWE-269
7.8
2021-06-24 CVE-2021-35448 Improper Privilege Management vulnerability in Remotemouse Emote Interactive Studio 3.008
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe.
local
low complexity
remotemouse CWE-269
7.8
2021-06-24 CVE-2021-29951 Improper Privilege Management vulnerability in Mozilla Firefox
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service.
network
low complexity
mozilla CWE-269
6.5
2021-06-24 CVE-2021-25650 Improper Privilege Management vulnerability in Avaya Aura Utility Services 7.0/7.0.1.2/7.1.3
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user.
local
low complexity
avaya CWE-269
8.8
2021-06-24 CVE-2021-25651 Improper Privilege Management vulnerability in Avaya Aura Utility Services 7.0/7.0.1.2/7.1.3
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges.
local
low complexity
avaya CWE-269
7.8
2021-06-09 CVE-2021-0052 Improper Privilege Management vulnerability in Intel Computing Improvement Program
Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially enable an escalation of privilege via local access.
local
low complexity
intel CWE-269
7.8
2021-06-09 CVE-2021-33356 Improper Privilege Management vulnerability in Raspap
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.
network
low complexity
raspap CWE-269
8.8