Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-06-30 CVE-2021-22326 Improper Privilege Management vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability.
local
low complexity
huawei CWE-269
7.1
2021-06-30 CVE-2021-22376 Improper Privilege Management vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a Improper Privilege Management vulnerability.
local
low complexity
huawei CWE-269
8.4
2021-06-30 CVE-2021-28692 Improper Privilege Management vulnerability in XEN
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands.
local
low complexity
xen CWE-269
7.1
2021-06-28 CVE-2021-35523 Improper Privilege Management vulnerability in Securepoint Openvpn-Client
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM.
local
low complexity
securepoint CWE-269
7.8
2021-06-24 CVE-2021-35448 Improper Privilege Management vulnerability in Remotemouse Emote Interactive Studio 3.008
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe.
local
low complexity
remotemouse CWE-269
7.8
2021-06-24 CVE-2021-29951 Improper Privilege Management vulnerability in Mozilla Firefox
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service.
network
low complexity
mozilla CWE-269
6.5
2021-06-24 CVE-2021-25650 Improper Privilege Management vulnerability in Avaya Aura Utility Services 7.0/7.0.1.2/7.1.3
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user.
local
low complexity
avaya CWE-269
8.8
2021-06-24 CVE-2021-25651 Improper Privilege Management vulnerability in Avaya Aura Utility Services 7.0/7.0.1.2/7.1.3
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges.
local
low complexity
avaya CWE-269
7.8
2021-06-18 CVE-2021-34810 Improper Privilege Management vulnerability in Synology Download Station
Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
network
low complexity
synology CWE-269
8.8
2021-06-09 CVE-2021-0052 Improper Privilege Management vulnerability in Intel Computing Improvement Program
Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially enable an escalation of privilege via local access.
local
low complexity
intel CWE-269
7.8