CWE-367— Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.— MITRE CWE catalog
700 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-367page 9 of 14
- CVE-2024-53032HIGHCVSS 7.8EG 7.82025-03-03
Memory corruption may occur in keyboard virtual device due to guest VM interaction.
- CVE-2024-53289HIGHCVSS 7.8EG 7.82024-12-11
Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- CVE-2024-53694HIGHCVSS 8.6EG 8.62025-03-07
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise una…
- CVE-2024-54084HIGHCVSS 7.5EG 7.52025-03-11
APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution.
- CVE-2024-5558MEDIUMCVSS 6.4EG 6.42024-06-12
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.
- CVE-2024-56337CRITICALCVSS 9.8EG 9.82024-12-20
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were E…
- CVE-2024-5803HIGHCVSS 7.5EG 7.52024-10-03
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.
- CVE-2024-6029MEDIUMCVSS 5.0EG 5.02025-04-30
Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Tesla Model S vehicles. Authentication is not required to expl…
- CVE-2024-6601MEDIUMCVSS 4.7EG 4.72024-07-09
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
- CVE-2024-6787MEDIUMCVSS 5.3EG 5.32024-09-21
This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbitrary files to the system. This could al…
- CVE-2024-7348HIGHCVSS 8.8EG 8.82024-08-08
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation …
- CVE-2024-7531MEDIUMCVSS 6.5EG 6.52024-08-06
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is …
- CVE-2024-9183HIGHCVSS 7.7EG 7.72025-12-05
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged user…
- CVE-2024-9512MEDIUMCVSS 5.3EG 5.32025-06-12
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary n…
- CVE-2025-0759LOWCVSS 3.3EG 3.32025-02-27
IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization.
- CVE-2025-13032CRITICALCVSS 9.9EG 9.92025-11-11
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overflow.
- CVE-2025-13818MEDIUMCVSS 6.7EG 6.72026-02-06
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
- CVE-2025-20028HIGHCVSS 7.1EG 7.12026-03-10
Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may ena…
- CVE-2025-20037HIGHCVSS 7.2EG 7.22025-08-12
Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-20074HIGHCVSS 7.8EG 7.82025-08-12
Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-20082HIGHCVSS 7.5EG 7.52025-05-13
Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to enable escalation of privilege via local access.
- CVE-2025-20740MEDIUMCVSS 4.7EG 4.72025-11-04
In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR0043…
- CVE-2025-21191HIGHCVSS 7.0EG 7.02025-04-08
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
- CVE-2025-21431MEDIUMCVSS 5.5EG 5.52025-04-07
Information disclosure may be there when a guest VM is connected.
- CVE-2025-21455HIGHCVSS 7.8EG 7.82025-08-06
Memory corruption while submitting blob data to kernel space though IOCTL.
- CVE-2025-21473HIGHCVSS 7.8EG 7.82025-08-06
Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
- CVE-2025-21485HIGHCVSS 7.8EG 7.82025-06-03
Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.
- CVE-2025-21746MEDIUMCVSS 4.7EG 5.52025-02-27
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics - fix crash when enabling pass-through port When enabling a pass-through port an interrupt might come before psmouse driver binds to the pass-through po…
- CVE-2025-21958MEDIUMCVSS 4.7EG 4.72025-04-01
In the Linux kernel, the following vulnerability has been resolved: Revert "openvswitch: switch to per-action label counting in conntrack" Currently, ovs_ct_set_labels() is only called for confirmed conntrack entries (ct) within ovs_ct_c…
- CVE-2025-21998MEDIUMCVSS 4.7EG 4.72025-04-03
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the TZ allocator, the efivars service is registered before the memory pool has be…
- CVE-2025-22060MEDIUMCVSS 4.7EG 4.72025-04-16
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: Prevent parser TCAM memory corruption Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM information, from concurrent modifications. Both the…
- CVE-2025-22224CRITICALCVSS 9.3EG 9.3⚠ KEV2025-03-04
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute c…
- CVE-2025-22394MEDIUMCVSS 6.7EG 6.72025-01-15
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code executio…
- CVE-2025-22850MEDIUMCVSS 5.6EG 5.62026-03-10
Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enabl…
- CVE-2025-23279HIGHCVSS 7.0EG 7.02025-08-02
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, in…
- CVE-2025-23359HIGHCVSS 8.3EG 8.32025-02-12
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vu…
- CVE-2025-24036HIGHCVSS 7.0EG 7.02025-02-11
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
- CVE-2025-2425MEDIUMCVSS 5.1EG 5.12025-07-18
Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system.
- CVE-2025-24430LOWCVSS 3.7EG 3.72025-02-11
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could e…
- CVE-2025-24432LOWCVSS 3.7EG 3.72025-02-11
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could e…
- CVE-2025-26620MEDIUMCVSS 6.3EG 6.32025-02-18
Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition when requesting access tokens using the client credentials flow. Concurrent …
- CVE-2025-27076HIGHCVSS 7.8EG 7.82025-08-06
Memory corruption while processing simultaneous requests via escape path.
- CVE-2025-27725MEDIUMCVSS 4.4EG 4.42025-11-11
Time-of-check time-of-use race condition for some ACAT before version 3.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack ma…
- CVE-2025-27812HIGHCVSS 8.1EG 8.12025-04-10
MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.
- CVE-2025-29833HIGHCVSS 7.7EG 7.72025-05-13
Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.
- CVE-2025-29969HIGHCVSS 7.5EG 7.52025-05-13
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
- CVE-2025-30101MEDIUMCVSS 4.4EG 4.42025-05-08
Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to den…
- CVE-2025-30663HIGHCVSS 8.8EG 8.82025-05-14
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2025-31146MEDIUMCVSS 6.1EG 6.12025-11-11
Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authentic…
- CVE-2025-32441MEDIUMCVSS 4.2EG 4.22025-05-07
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that sess…
Map vulnerabilities like CWE-367 to your infrastructure
EchelonGraph correlates every CVE — across CWE-367 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →