VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,597)

page 109 of 130
  • CVE-2026-54111HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-54107HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50384HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50356HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49808HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49806HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49803HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49802HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49784HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49183HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-48572HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-44800HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42900HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-57030MedJul 9, 2026
    risk 0.00cvss 5.9epss 0.00

    A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). As…

  • CVE-2026-55945MedJul 3, 2026
    risk 0.00cvss 4.2epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

  • CVE-2026-5120HigJul 1, 2026
    risk 0.00cvss 8.1epss 0.00

    A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from another user.

  • CVE-2026-43743MedJun 29, 2026
    risk 0.00cvss 4.7epss 0.00

    A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-46732MedJun 25, 2026
    risk 0.00cvss 6.7epss 0.00

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability,…

  • CVE-2026-21697HigJan 7, 2026
    risk 0.00cvss 8.1epss 0.00

    axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global `defaultClient` is mutated during request execution without synchronization, directly modifying the shared `http.Client`'s…

  • CVE-2025-66419HigDec 11, 2025
    risk 0.00cvss 8.8epss 0.00

    MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.