VYPR

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

BaseIncompleteLikelihood: Medium

Description

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-27 · CAPEC-29

CVEs mapped to this weakness (741)

page 8 of 38
  • CVE-2023-33046HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

  • CVE-2022-3701HigOct 27, 2023
    risk 0.51cvss 7.8epss 0.00

    A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.

  • CVE-2022-47631HigSep 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write…

  • CVE-2023-38141HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-33154HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Partition Management Driver Elevation of Privilege Vulnerability

  • CVE-2022-31639HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31638HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31637HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31636HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31635HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-43778HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

  • CVE-2022-43777HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

  • CVE-2022-27541HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

  • CVE-2022-27539HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

  • CVE-2023-21537HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

  • CVE-2022-36929HigJan 9, 2023
    risk 0.51cvss 7.8epss 0.00

    The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

  • CVE-2022-34325HigNov 14, 2022
    risk 0.51cvss 7.8epss 0.00

    DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the…

  • CVE-2022-21198HigNov 11, 2022
    risk 0.51cvss 7.9epss 0.00

    Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-22094HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2022-22093HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach IRQs from virtual interrupt sources in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile