VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,597)

page 107 of 130
  • CVE-2026-58527HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-56649MedJul 14, 2026
    risk 0.00cvss 5.9epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

  • CVE-2026-56188CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-54125HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50689HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50677HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50676HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50672HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50669HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50667HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.02

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50503HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50460HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-50458HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50457HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50452HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-50450HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50440HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50427HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50414HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50404HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.