← Back
CWE-367

696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

JSON object

Loading...

CVEs (696)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4365 Apps
OfficeOffice Long Term Servicing Channel+1 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Microsoft Outlook Security Feature Bypass Vulnerability
1Microsoft
1Malware Protection Engine
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Microsoft Defender Elevation of Privilege Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Windows Partition Management Driver Elevation of Privilege Vulnerability
1Hp
59200 G3 Firmware
200 G4 22 All In One Firmware200 Pro G4 22 All In One Firmware+56 more
Jun 17, 2026
Jun 30, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to...Show more
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jun 28, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged w...Show more
An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorizationShow less
2Linux
Netapp
6H300s
H410cH410s+3 more
Jun 17, 2026
Jun 28, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduc...Show more
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.Show less
1Trendmicro
1Apex One
Jun 17, 2026
Jun 26, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must f...Show more
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32554.Show less
1Trendmicro
1Apex One
Jun 17, 2026
Jun 26, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must f...Show more
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32555.Show less
1Netskope
1Netskope
Jun 17, 2026
Jun 15, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. The files are created and written with a SY...Show more
The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. The files are created and written with a SYSTEM account except one file (logplaceholder) which inherits permission giving all users full access control list. Netskope client restricts access to this file by allowing only read permissions as a standard user. Whenever the Netskope client service restarts, it deletes the logplaceholder and recreates, creating a race condition, which can be exploited by a malicious local user to create the file and set ACL permissions on the file. Once the file is created by a malicious user with proper ACL permissions, all files within C:\Users\Public\netSkope\ becomes modifiable by the unprivileged user. By using Windows pseudo-symlink, these files can be pointed to other places in the system and thus malicious users will be able to elevate privileges. Show less
1Hp
291Elite Dragonfly Firmware
Elite Dragonfly G2 FirmwareElite Dragonfly G3 Firmware+288 more
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
1Hp
291Elite Dragonfly Firmware
Elite Dragonfly G2 FirmwareElite Dragonfly G3 Firmware+288 more
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
1Hp
291Elite Dragonfly Firmware
Elite Dragonfly G2 FirmwareElite Dragonfly G3 Firmware+288 more
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
1Microsoft
1Nuget
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
NuGet Client Remote Code Execution Vulnerability
1Hp
403Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+400 more
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and inf...Show more
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.Show less
1Hp
403Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+400 more
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and inf...Show more
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.Show less
1Hp
403Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+400 more
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and inf...Show more
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.Show less
1Hp
403Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+400 more
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and inf...Show more
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.Show less
1Hp
403Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+400 more
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and inf...Show more
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.Show less
1Hp
387Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+384 more
Jun 17, 2026
Jun 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
1Hp
387Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+384 more
Jun 17, 2026
Jun 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.