Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-07-17 CVE-2020-9669 Improper Privilege Management vulnerability in Adobe Creative Cloud
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability.
network
low complexity
adobe CWE-269
critical
9.8
2020-07-15 CVE-2020-10286 Improper Privilege Management vulnerability in Ufactory products
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.
low complexity
ufactory CWE-269
8.8
2020-07-14 CVE-2020-1431 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.8
2020-07-14 CVE-2020-1416 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
network
low complexity
microsoft CWE-269
8.8
2020-07-14 CVE-2020-1412 Improper Privilege Management vulnerability in Microsoft products
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-269
8.8
2020-07-14 CVE-2020-7578 Improper Privilege Management vulnerability in Siemens Opcenter Execution Core
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2).
network
low complexity
siemens CWE-269
8.1
2020-07-14 CVE-2020-11956 Improper Privilege Management vulnerability in Rittal products
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices.
network
low complexity
rittal CWE-269
critical
9.8
2020-07-06 CVE-2020-6013 Improper Privilege Management vulnerability in Checkpoint Zonealarm Extreme Security
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.
network
low complexity
checkpoint CWE-269
8.8
2020-07-03 CVE-2020-7283 Improper Privilege Management vulnerability in Mcafee Total Protection
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to.
local
low complexity
mcafee CWE-269
8.8
2020-07-03 CVE-2020-7281 Improper Privilege Management vulnerability in Mcafee Total Protection
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file.
local
high complexity
mcafee CWE-269
6.3