Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-07-08 CVE-2021-25429 Improper Privilege Management vulnerability in Google Android
Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
low complexity
google CWE-269
3.3
2021-07-07 CVE-2021-21786 Improper Privilege Management vulnerability in Iobit Advanced Systemcare Ultimate 14.2.0.220
A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220.
local
low complexity
iobit CWE-269
4.6
2021-07-02 CVE-2021-34527 Improper Privilege Management vulnerability in Microsoft products
<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations.
network
low complexity
microsoft CWE-269
8.8
2021-06-30 CVE-2021-22326 Improper Privilege Management vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability.
local
low complexity
huawei CWE-269
6.6
2021-06-30 CVE-2021-22376 Improper Privilege Management vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a Improper Privilege Management vulnerability.
local
low complexity
huawei CWE-269
7.2
2021-06-30 CVE-2021-28692 Improper Privilege Management vulnerability in XEN
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands.
local
low complexity
xen CWE-269
5.6
2021-06-28 CVE-2021-35523 Improper Privilege Management vulnerability in Securepoint Openvpn-Client
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM.
local
low complexity
securepoint CWE-269
7.2
2021-06-24 CVE-2021-35448 Improper Privilege Management vulnerability in Remotemouse Emote Interactive Studio 3.008
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe.
local
low complexity
remotemouse CWE-269
7.2
2021-06-24 CVE-2021-29951 Improper Privilege Management vulnerability in Mozilla Firefox
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service.
network
low complexity
mozilla CWE-269
6.4
2021-06-24 CVE-2021-25650 Improper Privilege Management vulnerability in Avaya Aura Utility Services 7.0/7.0.1.2/7.1.3
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user.
local
low complexity
avaya CWE-269
8.8