CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2023-20217 MEDIUM
Cisco ThousandEyes Enterprise Agent - Privilege Escalation
CVSS 5.5
CVE-2023-32486 MEDIUM
Dell PowerScale OneFS 9.5.0.0-9.5.0.3 - Privilege Escalation
CVSS 6.7
CVE-2023-38641 HIGH
SICAM TOOLBOX II <V07.10 - Privilege Escalation
CVSS 7.8
CVE-2023-39508 HIGH
Apache Airflow < 2.6.0 - Authenticated Privilege Escalation and DAG Access Bypass via Run Task Feature
CVSS 8.8
CVE-2023-39261 MEDIUM
JetBrains IntelliJ IDEA <2023.2 - Privilege Escalation
CVSS 5.2
CVE-2023-20210 MEDIUM
Cisco BroadWorks - Privilege Escalation
CVSS 6.0
CVE-2023-34118 HIGH
Zoom Rooms for Windows <5.14.5 - Privilege Escalation
CVSS 7.3
CVE-2023-25521 HIGH
NVIDIA DGX A100/A800 Firmware < 1.21 - Privilege Escalation via SBIOS Input Parameter Validation
CVSS 7.5
CVE-2023-2002 MEDIUM
Linux Kernel < 6.4 - Unauthorized Bluetooth Management Command Execution via HCI Sockets
CVSS 6.8
CVE-2023-32080 CRITICAL
Wings <1.7.5 & 1.11.0 <1.11.6 - Code Injection
CVSS 9.0
CVE-2023-1966 HIGH
Instruments with Illumina Universal Copy Service v1.x-v2.x - Privil...
CVSS 7.4
CVE-2023-0664 HIGH
QEMU Guest Agent - Privilege Escalation
CVSS 7.8
CVE-2023-27247 MEDIUM
Cynet Client Agent <4.6.0.8010 - Privilege Escalation
CVSS 4.4
CVE-2023-27010 HIGH
Wondershare Dr.Fone <12.9.6 - Privilege Escalation
CVSS 7.8
CVE-2022-38695 HIGH
Unisoc SC9863A/T310/T610/T618/T606/T612/T616/T760/T770/T820/S8000 - Local Privilege Escalation via BootRom Command Index
CVSS 7.8
CVE-2022-38694 HIGH
Unisoc SC9863A/T310/T610/T618 - Local Privilege Escalation via Unchecked BootRom Write Address
CVSS 7.8
CVE-2022-38691 HIGH
Unisoc SC9863A/T310/T610/T618 - Local Privilege Escalation via BootROM Certificate Type Validation Bypass
CVSS 7.8
CVE-2022-34384 HIGH
Dell SupportAssist and Update < 4.5.0 - Local Privilege Escalation in Advanced Driver Restore
CVSS 7.8
CVE-2022-41290 HIGH
IBM AIX <7.4 - Privilege Escalation
CVSS 8.4
CVE-2022-43553 HIGH
EdgeMax EdgeRouter Firmware < 2.0.9-hotfix.5 - Authenticated Remote Code Execution via Operator Account
CVSS 8.8
CVE-2022-3088 HIGH
UC-8100A-ME-T <v3.5 - Path Traversal
CVSS 7.8
CVE-2022-41950 MEDIUM
super_xray 0.2-beta - Privilege Escalation via Inaccurate Default Permissions
CVSS 6.4
CVE-2022-44544 CRITICAL
Mahara 21.04.0-21.04.6, 21.10.0-21.10.4, 22.04.0-22.04.2 - Remote Code Execution via PDF Export with Ghostscript
CVSS 9.8
CVE-2022-39286 HIGH
Jupyter Core <4.11.2 - Code Injection
CVSS 8.8
CVE-2022-22239 HIGH
Juniper Networks Junos OS Evolved - Privilege Escalation
CVSS 8.2
Details
Vulnerabilities 341
Exploit Likelihood Medium