VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,607)

page 34 of 131
  • CVE-2025-49690HigJul 8, 2025
    risk 0.48cvss 7.4epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.

  • CVE-2023-52553HigApr 8, 2024
    risk 0.48cvss 7.4epss 0.00

    Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-21881HigJan 11, 2022
    risk 0.48cvss 7.0epss 0.25

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2021-41025HigDec 8, 2021
    risk 0.48cvss 7.3epss 0.01

    Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with improper…

  • CVE-2021-37069HigDec 8, 2021
    risk 0.48cvss 7.4epss 0.01

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.

  • CVE-2021-0244HigApr 22, 2021
    risk 0.48cvss 7.4epss 0.01

    A signal handler race condition exists in the Layer 2 Address Learning Daemon (L2ALD) of Juniper Networks Junos OS due to the absence of a specific protection mechanism to avoid a race condition which may allow an attacker to bypass the storm-control feature on devices. This…

  • CVE-2020-11277HigFeb 22, 2021
    risk 0.48cvss 7.4epss 0.00

    Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during async session in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2019-15879HigMay 13, 2020
    risk 0.48cvss 7.4epss 0.01

    In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it was freed, allowing an unprivileged process can overwrite…

  • CVE-2019-2213HigNov 13, 2019
    risk 0.48cvss 7.4epss 0.00

    In binder_free_transaction of binder.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2017-12410HigMar 26, 2018
    risk 0.48cvss 7.4epss 0.00

    It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working and/or temporary folders. Successful exploitation results in…

  • CVE-2016-6516HigAug 6, 2016
    risk 0.48cvss 7.4epss 0.01

    Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.

  • CVE-2013-1292HigApr 9, 2013
    risk 0.48cvss 7.4epss 0.01

    Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages…

  • CVE-2013-1278HigFeb 13, 2013
    risk 0.48cvss 7.4epss 0.01

    Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted…

  • CVE-2026-13197HigAug 14, 2026
    risk 0.47cvss epss 0.00

    Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local…

  • CVE-2026-34856HigApr 13, 2026
    risk 0.47cvss 7.3epss 0.00

    UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58316HigNov 28, 2025
    risk 0.47cvss 7.3epss 0.00

    DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-48548HigSep 4, 2025
    risk 0.47cvss 7.3epss 0.00

    In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for…

  • CVE-2025-20104HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-36262HigFeb 12, 2025
    risk 0.47cvss 7.2epss 0.00

    Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-56637HigDec 27, 2024
    risk 0.47cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Hold module reference while requesting a module User space may unload ip_set.ko while it is itself requesting a set type backend module, leading to a kernel crash. The race condition may be…