VYPR

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

BaseIncompleteLikelihood: Medium

Description

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-27 · CAPEC-29

CVEs mapped to this weakness (741)

page 15 of 38
  • CVE-2024-29062HigApr 9, 2024
    risk 0.46cvss 7.1epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2021-33632HigMar 25, 2024
    risk 0.46cvss 7.0epss 0.00

    Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad…

  • CVE-2024-21433HigMar 12, 2024
    risk 0.46cvss 7.0epss 0.05

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2024-1563HigFeb 22, 2024
    risk 0.46cvss 8.1epss 0.00

    An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.

  • CVE-2024-21371HigFeb 13, 2024
    risk 0.46cvss 7.0epss 0.11

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-46725HigNov 2, 2023
    risk 0.46cvss 8.1epss 0.00

    FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network module, a manufacturer account can use the `/api/updateProducts.json` endpoint to make the server send a…

  • CVE-2023-38041HigOct 25, 2023
    risk 0.46cvss 7.0epss 0.01

    A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.

  • CVE-2023-27470HigSep 11, 2023
    risk 0.46cvss 7.0epss 0.01

    BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.

  • CVE-2023-37250HigAug 20, 2023
    risk 0.46cvss 7.0epss 0.00

    Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of…

  • CVE-2023-35378HigAug 8, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Projected File System Elevation of Privilege Vulnerability

  • CVE-2023-26299HigJun 30, 2023
    risk 0.46cvss 7.0epss 0.00

    A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

  • CVE-2023-32555HigJun 26, 2023
    risk 0.46cvss 7.0epss 0.00

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2023-32554HigJun 26, 2023
    risk 0.46cvss 7.0epss 0.00

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2022-4149HigJun 15, 2023
    risk 0.46cvss 7.0epss 0.00

    The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. The files are created and written with a SYSTEM account except one file (logplaceholder) which…

  • CVE-2022-31642HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31641HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31640HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2023-25394HigMay 17, 2023
    risk 0.46cvss 7.0epss 0.00

    Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.

  • CVE-2023-24861HigMar 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2022-32477HigFeb 15, 2023
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This attack…