CWE-269 · 3 258 записей
Некорректное управление привилегиями
Почему это происходит?
Для упрощения развёртывания сервисной учётной записи выдаются широкие права на уровне всего кластера. Принцип минимальных привилегий на этапе установки игнорируется.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
kind: ClusterRolerules: - apiGroups: ["*"] resources: ["*"] verbs: ["*"]Исправленный код
kind: Rolemetadata: namespace: lodos-systemrules: - apiGroups: ["apps"] resources: ["deployments"] verbs: ["get", "list", "update"]Как предотвратить
- 01Выдавайте сервисным учётным записям права только в пределах их пространства имён.
- 02Избегайте подстановочных (*) ресурсов и действий.
- 03Регулярно и автоматически проверяйте привязки ролей.
CVE этого класса
3 264 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2017-5689Готовый эксплойт | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Критическая9,8 | KEV | 92,2 % | 2 мая 2017 г. |
96Срочно | CVE-2021-20021Готовый эксплойт | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a craftedsonicwall · email security · CWE-269 | Критическая9,8 | KEV | 88,7 % | 9 апр. 2021 г. |
80Срочно | CVE-2016-0151Готовый эксплойт | The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold microsoft · windows 10 1507 · CWE-269 | Высокая7,8 | KEV | 62,9 % | 12 апр. 2016 г. |
79На этой неделе | CVE-2020-8655Готовый эксплойт | An issue was discovered in EyesOfNetwork 5.3.eyesofnetwork · eyesofnetwork · CWE-269 | Высокая7,8 | KEV | 60,1 % | 6 февр. 2020 г. |
70На этой неделе | CVE-2019-1405Готовый эксплойт | An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creationmicrosoft · windows 10 1507 · CWE-269 | Высокая7,8 | KEV | 30,0 % | 12 нояб. 2019 г. |
69На этой неделе | CVE-2017-12635Готовый эксплойт | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x bapache · couchdb · CWE-269 | Критическая9,8 | — | 99,8 % | 14 нояб. 2017 г. |
69На этой неделе | CVE-2022-24637Готовый эксплойт | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gopenwebanalytics · open web analytics · CWE-269 | Критическая9,8 | — | 99,1 % | 18 мар. 2022 г. |
69На этой неделе | CVE-2024-49035Готовый эксплойт | Partner.Microsoft.Com Elevation of Privilege Vulnerabilitymicrosoft · partner center · CWE-269 | Критическая9,8 | KEV | 1,3 % | 26 нояб. 2024 г. |
69На этой неделе | CVE-2026-84869Готовый эксплойт | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actionsconnectwise · screenconnect · CWE-269 | Критическая9,9 | KEV | 0,9 % | 8 сент. 2026 г. |
69На этой неделе | CVE-2026-46817Готовый эксплойт | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).oracle · e-business suite · CWE-269 | Критическая9,8 | KEV | 0,8 % | 28 мая 2026 г. |
68На этой неделе | CVE-2013-0643Готовый эксплойт | The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 anadobe · flash player · CWE-269 | Высокая8,8 | KEV | 10,5 % | 26 февр. 2013 г. |
67На этой неделе | CVE-2019-1215Готовый эксплойт | An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Prmicrosoft · windows 10 1507 · CWE-269 | Высокая7,8 | KEV | 19,3 % | 11 сент. 2019 г. |
67На этой неделе | CVE-2023-28434Готовый эксплойт | MinIO is vulnerable to privilege escalation on Linux/MacOSminio · minio · CWE-269 | Высокая8,8 | KEV | 7,9 % | 22 мар. 2023 г. |
65На этой неделе | CVE-2022-0441Готовый эксплойт | MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creationstylemixthemes · masterstudy lms · CWE-269 | Критическая9,8 | — | 85,3 % | 7 мар. 2022 г. |
64На этой неделе | CVE-2014-1511Готовый эксплойт | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypamozilla · firefox · CWE-269 | Критическая9,8 | — | 83,6 % | 19 мар. 2014 г. |
64На этой неделе | CVE-2014-1510Готовый эксплойт | The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 mozilla · firefox · CWE-269 | Критическая9,8 | — | 82,3 % | 19 мар. 2014 г. |
64На этой неделе | CVE-2019-1388Готовый эксплойт | An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Winmicrosoft · windows 10 1507 · CWE-269 | Высокая7,8 | KEV | 8,6 % | 12 нояб. 2019 г. |
63На этой неделе | CVE-2021-38540Proof of concept | Apache Airflow: Variable Import endpoint missed authentication checkapache · airflow · CWE-269 | Критическая9,8 | — | 80,9 % | 9 сент. 2021 г. |
63На этой неделе | CVE-2020-3950Готовый эксплойт | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior bvmware · fusion · CWE-269 | Высокая7,8 | KEV | 7,3 % | 17 мар. 2020 г. |
63На этой неделе | CVE-2024-38014Готовый эксплойт | Windows Installer Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-269 | Высокая7,8 | KEV | 6,3 % | 10 сент. 2024 г. |
62На этой неделе | CVE-2020-13638Proof of concept | lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation.rconfig · rconfig · CWE-269 | Критическая9,8 | — | 76,6 % | 13 нояб. 2020 г. |
62На этой неделе | CVE-2002-0367Готовый эксплойт | smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which almicrosoft · windows 2000 · CWE-269 | Высокая7,8 | KEV | 4,9 % | 25 июн. 2002 г. |
62На этой неделе | CVE-2026-21533Готовый эксплойт | Windows Remote Desktop Services Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-269 | Высокая7,8 | KEV | 4,1 % | 10 февр. 2026 г. |
62На этой неделе | CVE-2024-26169Готовый эксплойт | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-269 | Высокая7,8 | KEV | 4,0 % | 12 мар. 2024 г. |
62На этой неделе | CVE-2023-35674Готовый эксплойт | In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code.google · android · CWE-269 | Высокая7,8 | KEV | 2,6 % | 11 сент. 2023 г. |
- CVE-2017-568997Срочно
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %intel · active management technology firmware2 мая 2017 г.
- CVE-2021-2002196Срочно
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 89 %sonicwall · email security9 апр. 2021 г.
- CVE-2016-015180Срочно
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 63 %microsoft · windows 10 150712 апр. 2016 г.
- CVE-2020-865579На этой неделе
An issue was discovered in EyesOfNetwork 5.3.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 60 %eyesofnetwork · eyesofnetwork6 февр. 2020 г.
- CVE-2019-140570На этой неделе
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 30 %microsoft · windows 10 150712 нояб. 2019 г.
- CVE-2017-1263569На этой неделе
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x b
КритическаяCVSS 9,8Готовый эксплойтEPSS 100 %apache · couchdb14 нояб. 2017 г.
- CVE-2022-2463769На этой неделе
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to g
КритическаяCVSS 9,8Готовый эксплойтEPSS 99 %openwebanalytics · open web analytics18 мар. 2022 г.
- CVE-2024-4903569На этой неделе
Partner.Microsoft.Com Elevation of Privilege Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 1 %microsoft · partner center26 нояб. 2024 г.
- CVE-2026-8486969На этой неделе
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 1 %connectwise · screenconnect8 сент. 2026 г.
- CVE-2026-4681769На этой неделе
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 1 %oracle · e-business suite28 мая 2026 г.
- CVE-2013-064368На этой неделе
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 an
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 11 %adobe · flash player26 февр. 2013 г.
- CVE-2019-121567На этой неделе
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Pr
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 19 %microsoft · windows 10 150711 сент. 2019 г.
- CVE-2023-2843467На этой неделе
MinIO is vulnerable to privilege escalation on Linux/MacOS
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 8 %minio · minio22 мар. 2023 г.
- CVE-2022-044165На этой неделе
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
КритическаяCVSS 9,8Готовый эксплойтEPSS 85 %stylemixthemes · masterstudy lms7 мар. 2022 г.
- CVE-2014-151164На этой неделе
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypa
КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %mozilla · firefox19 мар. 2014 г.
- CVE-2014-151064На этой неделе
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %mozilla · firefox19 мар. 2014 г.
- CVE-2019-138864На этой неделе
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Win
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 9 %microsoft · windows 10 150712 нояб. 2019 г.
- CVE-2021-3854063На этой неделе
Apache Airflow: Variable Import endpoint missed authentication check
КритическаяCVSS 9,8Proof of conceptEPSS 81 %apache · airflow9 сент. 2021 г.
- CVE-2020-395063На этой неделе
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior b
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 7 %vmware · fusion17 мар. 2020 г.
- CVE-2024-3801463На этой неделе
Windows Installer Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 6 %microsoft · windows 10 150710 сент. 2024 г.
- CVE-2020-1363862На этой неделе
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation.
КритическаяCVSS 9,8Proof of conceptEPSS 77 %rconfig · rconfig13 нояб. 2020 г.
- CVE-2002-036762На этой неделе
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which al
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 5 %microsoft · windows 200025 июн. 2002 г.
- CVE-2026-2153362На этой неделе
Windows Remote Desktop Services Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 4 %microsoft · windows 10 160710 февр. 2026 г.
- CVE-2024-2616962На этой неделе
Windows Error Reporting Service Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 4 %microsoft · windows 10 150712 мар. 2024 г.
- CVE-2023-3567462На этой неделе
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 3 %google · android11 сент. 2023 г.