CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
Description
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-27 · CAPEC-29
CVEs mapped to this weakness (741)
page 8 of 38| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33046 | Hig | 0.51 | 7.8 | 0.00 | Feb 6, 2024 | Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation. | ||
| CVE-2022-3701 | Hig | 0.51 | 7.8 | 0.00 | Oct 27, 2023 | A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges. | ||
| CVE-2022-47631 | Hig | 0.51 | 7.8 | 0.00 | Sep 14, 2023 | Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write… | ||
| CVE-2023-38141 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-33154 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2023 | Windows Partition Management Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-31639 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2023 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | ||
| CVE-2022-31638 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2023 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | ||
| CVE-2022-31637 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2023 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | ||
| CVE-2022-31636 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2023 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | ||
| CVE-2022-31635 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2023 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | ||
| CVE-2022-43778 | Hig | 0.51 | 7.8 | 0.00 | Jun 12, 2023 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | ||
| CVE-2022-43777 | Hig | 0.51 | 7.8 | 0.00 | Jun 12, 2023 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | ||
| CVE-2022-27541 | Hig | 0.51 | 7.8 | 0.00 | Jun 12, 2023 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | ||
| CVE-2022-27539 | Hig | 0.51 | 7.8 | 0.00 | Jun 12, 2023 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | ||
| CVE-2023-21537 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | ||
| CVE-2022-36929 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2023 | The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user. | ||
| CVE-2022-34325 | Hig | 0.51 | 7.8 | 0.00 | Nov 14, 2022 | DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the… | ||
| CVE-2022-21198 | Hig | 0.51 | 7.9 | 0.00 | Nov 11, 2022 | Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2022-22094 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2022-22093 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach IRQs from virtual interrupt sources in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.
- risk 0.51cvss 7.8epss 0.00
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.
- risk 0.51cvss 7.8epss 0.00
Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write…
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Partition Management Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.00
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.00
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.00
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.00
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.00
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.00
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.00
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.00
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
- risk 0.51cvss 7.8epss 0.01
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.
- risk 0.51cvss 7.8epss 0.00
DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the…
- risk 0.51cvss 7.9epss 0.00
Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach IRQs from virtual interrupt sources in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile