CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 10 of 55
- CVE-2026-32165HIGHCVSS 7.8EG 7.82026-04-14
Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2026-32164HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2026-32163HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2026-32160HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2026-32159HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2026-32158HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2026-32153HIGHCVSS 7.8EG 7.82026-04-14
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- CVE-2026-32090HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
- CVE-2026-32089HIGHCVSS 7.8EG 7.82026-04-14
Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
- CVE-2026-27927HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-27918HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
- CVE-2026-27911HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2026-26181HIGHCVSS 7.8EG 7.82026-04-14
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-26172HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2026-26168HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-20930HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-23411HIGHCVSS 7.8EG 7.82026-04-01
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from the fi…
- CVE-2026-23410HIGHCVSS 7.8EG 7.82026-04-01
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads to a use-after-free situation: because the rawdata inodes are not refcounted, an attacker …
- CVE-2026-23393HIGHCVSS 7.8EG 7.82026-03-25
In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletion When a peer MEP is being deleted, cancel_delayed_work_sync() is called on ccm_rx_dwork before freeing. However, br_c…
- CVE-2026-23271HIGHCVSS 7.8EG 7.82026-03-20
In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specific…
- CVE-2026-23239HIGHCVSS 7.8EG 7.82026-03-10
In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_wo…
- CVE-2026-21231HIGHCVSS 7.8EG 7.82026-02-10
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-20924HIGHCVSS 7.8EG 7.82026-01-13
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20918HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20877HIGHCVSS 7.8EG 7.82026-01-13
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20874HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20873HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20867HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20866HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20861HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20858HIGHCVSS 7.8EG 7.82026-01-13
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2025-33235HIGHCVSS 7.8EG 7.82025-12-16
NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a race condition. A successful exploit of this vulnerability might lead to information disclosure, data tampering, denial…
- CVE-2025-64661HIGHCVSS 7.8EG 7.82025-12-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
- CVE-2025-43364HIGHCVSS 7.8EG 7.82025-11-04
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.1. An app may be able to break out of its sandbox.
- CVE-2025-55328HIGHCVSS 7.8EG 7.82025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-53768HIGHCVSS 7.8EG 7.82025-10-14
Use after free in Xbox allows an authorized attacker to elevate privileges locally.
- CVE-2025-53150HIGHCVSS 7.8EG 7.82025-10-14
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
- CVE-2025-55228HIGHCVSS 7.8EG 7.82025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- CVE-2025-55224HIGHCVSS 7.8EG 7.82025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- CVE-2025-54913HIGHCVSS 7.8EG 7.82025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.
- CVE-2025-54092HIGHCVSS 7.8EG 7.82025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-49665HIGHCVSS 7.8EG 7.82025-07-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.
- CVE-2025-48000HIGHCVSS 7.8EG 7.82025-07-08
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-31188HIGHCVSS 7.8EG 7.82025-03-31
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to bypass Privacy preferences.
- CVE-2024-47892HIGHCVSS 7.8EG 7.82024-12-13
Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.
- CVE-2024-46971HIGHCVSS 7.8EG 7.82024-12-13
Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.
- CVE-2024-48991HIGHCVSS 7.8EG 7.82024-11-19
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's …
- CVE-2024-43701HIGHCVSS 7.8EG 7.82024-10-14
Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.
- CVE-2024-38191HIGHCVSS 7.8EG 7.82024-08-13
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- CVE-2024-32908HIGHCVSS 7.8EG 7.82024-06-13
In sec_media_protect of media.c, there is a possible permission bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →