VYPR

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

BaseIncompleteLikelihood: Medium

Description

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-27 · CAPEC-29

CVEs mapped to this weakness (741)

page 6 of 38
  • CVE-2026-27750HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without…

  • CVE-2023-31324HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or…

  • CVE-2023-20548HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.

  • CVE-2026-21240HigFeb 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24071HigFeb 2, 2026
    risk 0.51cvss 7.8epss 0.00

    It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses…

  • CVE-2026-20831HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20816HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.02

    Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20809HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55696HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55680HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54895HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.

  • CVE-2025-20074HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-27076HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing simultaneous requests via escape path.

  • CVE-2025-21473HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.

  • CVE-2025-21455HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while submitting blob data to kernel space though IOCTL.

  • CVE-2025-21485HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.

  • CVE-2024-13961HigMay 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and…

  • CVE-2024-13960HigMay 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a…

  • CVE-2024-13944HigMay 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a…

  • CVE-2024-45565HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when blob structure is modified by user-space after kernel verification.