CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
Description
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-27 · CAPEC-29
CVEs mapped to this weakness (741)
page 6 of 38| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-27750 | Hig | 0.51 | 7.8 | 0.00 | Mar 5, 2026 | Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without… | ||
| CVE-2023-31324 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or… | ||
| CVE-2023-20548 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability. | ||
| CVE-2026-21240 | Hig | 0.51 | 7.8 | 0.00 | Feb 10, 2026 | Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24071 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses… | ||
| CVE-2026-20831 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20816 | Hig | 0.51 | 7.8 | 0.02 | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20809 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55696 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55680 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54895 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-20074 | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2025 | Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2025-27076 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing simultaneous requests via escape path. | ||
| CVE-2025-21473 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption when using Virtual cdm (Camera Data Mover) to write registers. | ||
| CVE-2025-21455 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while submitting blob data to kernel space though IOCTL. | ||
| CVE-2025-21485 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC. | ||
| CVE-2024-13961 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and… | ||
| CVE-2024-13960 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a… | ||
| CVE-2024-13944 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a… | ||
| CVE-2024-45565 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption when blob structure is modified by user-space after kernel verification. |
- risk 0.51cvss 7.8epss 0.00
Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without…
- risk 0.51cvss 7.8epss 0.00
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or…
- risk 0.51cvss 7.8epss 0.00
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses…
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.02
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing simultaneous requests via escape path.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while submitting blob data to kernel space though IOCTL.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.
- risk 0.51cvss 7.8epss 0.00
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and…
- risk 0.51cvss 7.8epss 0.00
Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a…
- risk 0.51cvss 7.8epss 0.00
Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a…
- risk 0.51cvss 7.8epss 0.00
Memory corruption when blob structure is modified by user-space after kernel verification.