CWE-367: CWE-367
Yearly Trend
Top Affected Vendors
All CWE-367 CVEs (174)
This Windows kernel vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a time-of-check-time...
Apr 9, 2024A local privilege escalation vulnerability in Lenovo Vantage SystemUpdate plugin allows attackers to execute arbitrary code with elevated privileges. ...
Oct 27, 2023CVE-2022-47631 is a local privilege escalation vulnerability in Razer Synapse software that allows attackers to gain administrative privileges on Wind...
Sep 14, 2023This Windows kernel vulnerability allows local attackers to exploit a race condition (CWE-367) to elevate privileges from user mode to kernel mode. It...
Sep 12, 2023This vulnerability in the Windows Partition Management Driver allows an authenticated attacker to execute arbitrary code with SYSTEM privileges. It af...
Jul 11, 2023A time-of-check to time-of-use (TOCTOU) vulnerability in the Linux kernel's io_uring subsystem allows a local user to escalate privileges to root. Thi...
Jun 28, 2023This CVE describes a time-of-check to time-of-use (TOCTOU) vulnerability in the BIOS of certain HP PC products. It could allow attackers to execute ar...
Jun 13, 2023This CVE describes a time-of-check to time-of-use (TOCTOU) vulnerability in HP PC BIOS firmware that could allow attackers to execute arbitrary code, ...
Jun 13, 2023This is a local privilege escalation vulnerability in Parallels Access Agent that allows attackers with initial low-privileged access to gain root pri...
Jul 18, 2022A local privilege escalation vulnerability exists in Lenovo System Interface Foundation's IMController component due to a Time-of-Check Time-of-Use (T...
May 18, 2022This vulnerability in Realtek RtsUpx USB Utility Driver allows local low-privileged users to execute arbitrary code with elevated privileges via a cra...
Nov 2, 2021This vulnerability allows non-secure clients to modify permissions on shared memory buffers while the system is waiting for callback responses in Qual...
Jun 9, 2021CVE-2020-1337 is a local privilege escalation vulnerability in the Windows Print Spooler service that allows authenticated attackers to write arbitrar...
Aug 17, 2020A local privilege escalation vulnerability exists in IBM Concert due to a race condition involving symbolic link handling. This allows authenticated l...
Dec 26, 2025This vulnerability in GitLab allows authenticated users to steal credentials from higher-privileged users and impersonate them under specific conditio...
Dec 5, 2025A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Windows Virtual Machine Bus allows local attackers to execute arbitrary code. Thi...
May 13, 2025ClipBucket v5 versions before 5.5.3 - #40 have a TOCTOU race condition in avatar/background image uploads. Attackers can upload malicious PHP files th...
Feb 10, 2026BullWall Server Intrusion Protection has a timing vulnerability where MFA checks for RDP connections have a configuration-dependent delay. Remote auth...
Dec 18, 2025A local, authenticated attacker can log into BullWall Server Intrusion Protection systems during the brief window after boot when login services are r...
Dec 18, 2025A time-of-check time-of-use race condition vulnerability in the UEFI firmware SmiVariable driver for specific Intel server boards allows a privileged ...
May 13, 2025A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Windows Fundamentals allows authenticated attackers to execute arbitrary code ove...
May 13, 2025This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in AMI's APTIOV BIOS firmware. An attacker with local access can ...
May 13, 2025This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in AMI's APTIOV BIOS firmware. An attacker with local access can ...
Mar 11, 2025This CVE describes a time-of-check time-of-use (TOCTOU) race condition vulnerability in Intel Battery Life Diagnostic Tool software. An authenticated ...
Feb 12, 2025CVE-2024-42444 is a TOCTOU race condition vulnerability in AMI APTIOV BIOS that allows local attackers to execute arbitrary code on affected devices. ...
Jan 14, 2025This vulnerability allows a local attacker to escalate privileges via COM hijack in AVG/Avast Antivirus when self-protection is disabled. It affects u...
Oct 3, 2024This CVE describes a TOCTOU (Time-Of-Check-Time-Of-Use) vulnerability in AMD System Management Mode (SMM) that could allow an attacker with ring0 priv...
Aug 13, 2024This vulnerability in OpenSSH allows attackers to perform timing attacks against password entry when echo is disabled (e.g., during su or sudo operati...
Jul 2, 2024This vulnerability is a time-of-check time-of-use (TOCTOU) race condition in Qualcomm modem firmware that allows a transient denial-of-service (DoS) a...
Apr 13, 2023A race condition vulnerability in McAfee Total Protection's QuickClean feature allows local users to elevate privileges and delete arbitrary files. Th...
Mar 10, 2022A Time-of-check Time-of-use (TOC/TOU) vulnerability in the Zoom Plugin for Microsoft Outlook on macOS allows standard users to write malicious applica...
Sep 27, 2021This vulnerability allows local attackers with high-privileged code execution on a Parallels Desktop guest system to escalate privileges to hypervisor...
Apr 29, 2021NestJS applications using Fastify platform with route-specific middleware are vulnerable to URL encoding bypass. This allows attackers to access prote...
Dec 29, 2025This CVE describes a Time-of-Check Time-of-Use (TOCTOU) vulnerability in GPU firmware where guest VM kernel/driver software can post improper commands...
Nov 17, 2025This CVE describes a time-of-check time-of-use (TOCTOU) vulnerability in Alcatel-Lucent ALE deskphones that allows authenticated attackers to replace ...
May 7, 2024This vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition in AMD's ASP bootloader that allows an attacker to tamper with SPI ROM data ...
May 9, 2023This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to potentially escape the browser sandbox via a craf...
Feb 11, 2022This vulnerability allows an attacker with guest VM access on AMD systems to bypass host OS security controls and potentially execute arbitrary code o...
Jul 22, 2021This CVE describes a time-of-check to time-of-use (TOCTOU) race condition vulnerability in Rufus versions 4.11 and below. When Rufus runs with Adminis...
Jan 22, 2026A time-of-check time-of-use race condition vulnerability in the Graphics Kernel allows authenticated local attackers to execute arbitrary code. This a...
Sep 9, 2025This vulnerability allows an attacker with administrative privileges to cause a Blue Screen of Death (BSOD) by manipulating memory access rights durin...
Dec 16, 2024A race condition vulnerability in Lapce v0.2.8 allows attackers to execute arbitrary code with elevated privileges. This affects users running the vul...
Sep 15, 2023A time-of-check time-of-use race condition vulnerability in Intel Converged Security and Management Engine firmware allows a privileged local user to ...
Aug 12, 2025This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in certain Intel processors with Intel ACTM technology. It allows...
Nov 13, 2024This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Distributed File System (DFS) services. Attackers can ...
Apr 9, 2024A race condition vulnerability in BIOS firmware for certain Intel processors allows a privileged user with local access to potentially escalate privil...
Mar 14, 2024This vulnerability in the NuGet client allows remote code execution when processing specially crafted packages. Attackers could execute arbitrary code...
Jun 14, 2023This CVE describes a local privilege escalation vulnerability in SevenCs ORCA G2 software where a TOCTOU race condition allows standard users to gain ...
Dec 31, 2025This CVE describes a local privilege escalation vulnerability in Nagios XI where low-privileged users can exploit race conditions during crontab insta...
Oct 30, 2025A time-of-check time-of-use race condition vulnerability in Microsoft Defender for Linux allows a local authenticated attacker to cause a denial of se...
Oct 14, 2025About CWE-367 (CWE-367)
Our database tracks 174 CVEs classified as CWE-367, with 16 rated critical and 119 rated high severity. The average CVSS score for CWE-367 vulnerabilities is 7.2.
External reference: View CWE-367 on MITRE CWE →
Monitor CWE-367 Vulnerabilities
Get alerted when new CWE-367 CVEs affect your infrastructure.
Start Monitoring Free