About “Privilege Escalation”

A curated feed of “Privilege Escalation”-related CVEs appears below. We currently track 7823 CVEs for this tag (all time). In the last 365 days, 1227 were published. Average CVSS is 7.7 (all time; 7.9 over 365d), and 84% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-269 - Improper Privilege Management, CWE-266 - Incorrect Privilege Assignment, CWE-862 - Missing Authorization.

In our taxonomy this topic maps to a LOW impact class. Vendor advisories and release notes are key. Verify compatibility matrices, prefer supported long term versions, and stage rollouts with monitoring. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2022-09-01
Critical

CVE-2022-36601

The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and ac…

High

CVE-2022-1729

A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as ker…

Critical

CVE-2022-36130

HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized…

2022-08-31
High

CVE-2022-2897

Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..

Medium

CVE-2022-31233

Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and ac…

High

CVE-2022-1976

A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable permission to create a string of requests that can cause a use-after-free flaw wi…

2022-08-26
Medium

CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns ano…

Medium

CVE-2021-32570

In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly p…

2022-08-23
High

CVE-2022-31676

VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root…

2022-08-22
High

CVE-2022-30605

A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An a…

2022-08-21
High

CVE-2022-2921

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An a…

2022-08-18
Medium

CVE-2022-2568

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser a…

High

CVE-2022-29549

An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure that a program was in…

2022-08-17
High

CVE-2022-28752

Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could exploit this vulnerabilit…

High

CVE-2022-31262

An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and chan…

2022-08-16
High

CVE-2022-34256

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An at…

High

CVE-2022-34255

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An a…

High

CVE-2021-30490

upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege esc…

High

CVE-2022-24949

A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a race condition, buffer overflow, and logic bug all in PipeSocketHandler::listen().

2022-08-15
High

CVE-2022-34711

Windows Defender Credential Guard Elevation of Privilege Vulnerability

2022-08-11
High

CVE-2022-34235

Adobe Premiere Elements version 2020v20 (and earlier) is affected by an Uncontrolled Search Path Element which could lead to Privilege Escalation. An attacker could leverage this vulnerability to obt…

2022-08-10
Critical

CVE-2022-37002

The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.

High

CVE-2022-31672

VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.

2022-08-09
High

CVE-2022-35820

Windows Bluetooth Driver Elevation of Privilege Vulnerability

Medium

CVE-2022-35819

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35818

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35817

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35816

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35815

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35814

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35813

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35812

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35811

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35810

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35809

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35808

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35807

Azure Site Recovery Elevation of Privilege Vulnerability

High

CVE-2022-35802

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35801

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35800

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35799

Azure Site Recovery Elevation of Privilege Vulnerability

High

CVE-2022-35796

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

High

CVE-2022-35795

Windows Error Reporting Service Elevation of Privilege Vulnerability

High

CVE-2022-35793

Windows Print Spooler Elevation of Privilege Vulnerability

High

CVE-2022-35792

Storage Spaces Direct Elevation of Privilege Vulnerability

Medium

CVE-2022-35791

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35790

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35789

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35788

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35787

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35786

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35785

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35784

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35783

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35782

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35781

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35780

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35775

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-35774

Azure Site Recovery Elevation of Privilege Vulnerability

High

CVE-2022-35771

Windows Defender Credential Guard Elevation of Privilege Vulnerability

High

CVE-2022-35768

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-35765

Storage Spaces Direct Elevation of Privilege Vulnerability

High

CVE-2022-35764

Storage Spaces Direct Elevation of Privilege Vulnerability

High

CVE-2022-35763

Storage Spaces Direct Elevation of Privilege Vulnerability

High

CVE-2022-35762

Storage Spaces Direct Elevation of Privilege Vulnerability

High

CVE-2022-35761

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-35760

Microsoft ATA Port Driver Elevation of Privilege Vulnerability

High

CVE-2022-34707

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-34706

Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

High

CVE-2022-34705

Windows Defender Credential Guard Elevation of Privilege Vulnerability

High

CVE-2022-34703

Windows Partition Management Driver Elevation of Privilege Vulnerability

High

CVE-2022-34699

Windows Win32k Elevation of Privilege Vulnerability

High

CVE-2022-34691

Active Directory Domain Services Elevation of Privilege Vulnerability

High

CVE-2022-34690

Windows Fax Service Elevation of Privilege Vulnerability

High

CVE-2022-33670

Windows Partition Management Driver Elevation of Privilege Vulnerability

High

CVE-2022-33646

Azure Batch Node Agent Elevation of Privilege Vulnerability

High

CVE-2022-33640

System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability

High

CVE-2022-24516

Microsoft Exchange Server Elevation of Privilege Vulnerability

High

CVE-2022-24477

Microsoft Exchange Server Elevation of Privilege Vulnerability

High

CVE-2022-21980

Microsoft Exchange Server Elevation of Privilege Vulnerability

Medium

CVE-2022-30573

The ftlserver component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, and TIBCO FTL - Enterprise Edition contains an easily ex…

2022-08-08
Critical

CVE-2022-35490

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidat…

2022-08-05
High

CVE-2022-31664

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

High

CVE-2022-31661

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.

High

CVE-2022-31660

VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

2022-08-04
High

CVE-2022-35735

In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with Resource Administrator or Manager privileges can…

High

CVE-2022-34158

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Furth…

2022-08-01
High

CVE-2022-26310

Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user wit…

Low

CVE-2022-26309

Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group.

2022-07-30
High

CVE-2022-33158

Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escala…

2022-07-28
High

CVE-2021-39088

IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privilege escalation could be performed. IBM X-Force ID…

2022-07-23
Medium

CVE-2022-36414

There is an elevation of privilege breakout vulnerability in the Windows EXE installer in Scooter Beyond Compare 4.2.0 through 4.4.2 before 4.4.3. Affected versions allow a logged-in user to run appl…

2022-07-21
Medium

CVE-2022-28877

This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can be abused for local privilege escalation on affected F-Secure & WithSecure wind…

Medium

CVE-2022-22555

Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands o…

2022-07-19
High

CVE-2022-30526

A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 fir…

2022-07-18
High

CVE-2022-32450

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM wh…

2022-07-17
High

CVE-2022-30550

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and m…

2022-07-14
High

CVE-2021-45492

In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. However, this direc…

2022-07-13
High

CVE-2022-20212

In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution pri…

2022-07-12
High

CVE-2022-33677

Azure Site Recovery Elevation of Privilege Vulnerability

High

CVE-2022-33675

Azure Site Recovery Elevation of Privilege Vulnerability

High

CVE-2022-33674

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33673

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33672

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33671

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33669

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33668

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33667

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33666

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33665

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33664

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33663

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33662

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33661

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33660

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33659

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33658

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33657

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33656

Azure Site Recovery Elevation of Privilege Vulnerability

Medium

CVE-2022-33655

Azure Site Recovery Elevation of Privilege Vulnerability