CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 11 of 55
- CVE-2024-30031HIGHCVSS 7.8EG 7.82024-05-14
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- CVE-2024-29863HIGHCVSS 7.8EG 7.82024-04-05
A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Ad…
- CVE-2022-3328HIGHCVSS 7.8EG 7.82024-01-08
Race condition in snap-confine's must_mkdir_and_open_with_perms()
- CVE-2023-33110HIGHCVSS 7.8EG 7.82024-01-02
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session inde…
- CVE-2023-35362HIGHCVSS 7.8EG 7.82023-07-11
Windows Clip Service Elevation of Privilege Vulnerability
- CVE-2022-31645HIGHCVSS 7.8EG 7.82023-06-14
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- CVE-2022-41100HIGHCVSS 7.8EG 7.82022-11-09
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-41093HIGHCVSS 7.8EG 7.82022-11-09
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-41045HIGHCVSS 7.8EG 7.82022-11-09
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-34696HIGHCVSS 7.8EG 7.82022-08-09
Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2022-34892HIGHCVSS 7.8EG 7.82022-07-18
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in orde…
- CVE-2021-3922HIGHCVSS 7.8EG 7.82022-05-18
A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMController child proces…
- CVE-2022-29113HIGHCVSS 7.8EG 7.82022-05-10
Windows Digital Media Receiver Elevation of Privilege Vulnerability
- CVE-2022-24537HIGHCVSS 7.8EG 7.82022-04-15
Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2022-22008HIGHCVSS 7.8EG 7.82022-04-15
Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2022-24986HIGHCVSS 7.8EG 7.82022-02-26
KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling t…
- CVE-2021-44731HIGHCVSS 7.8EG 7.82022-02-17
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private m…
- CVE-2021-0652HIGHCVSS 7.8EG 7.82021-10-22
In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects. This could lead to local escalation of privilege with no additional execution pri…
- CVE-2021-0483HIGHCVSS 7.8EG 7.82021-10-22
In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Produ…
- CVE-2021-28701HIGHCVSS 7.8EG 7.82021-09-08
Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, …
- CVE-2021-28697HIGHCVSS 7.8EG 7.82021-08-27
grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant tab…
- CVE-2021-34462HIGHCVSS 7.8EG 7.82021-07-16
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
- CVE-2021-21117HIGHCVSS 7.8EG 7.82021-02-09
Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file.
- CVE-2020-9990HIGHCVSS 7.8EG 7.82020-10-22
A race condition was addressed with additional validation. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with kernel privileges.
- CVE-2020-15567HIGHCVSS 7.8EG 7.82020-07-07
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in …
- CVE-2020-15530HIGHCVSS 7.8EG 7.82020-07-05
An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAMFILES(X86)%\Steam have weak permissions …
- CVE-2020-15396HIGHCVSS 7.8EG 7.82020-06-30
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
- CVE-2020-11492HIGHCVSS 7.8EG 7.82020-06-05
An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which…
- CVE-2020-13173HIGHCVSS 7.8EG 7.82020-05-28
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive …
- CVE-2020-1021HIGHCVSS 7.8EG 7.82020-05-21
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfu…
- CVE-2020-11739HIGHCVSS 7.8EG 7.82020-04-14
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memo…
- CVE-2019-5228HIGHCVSS 7.8EG 7.82019-11-12
Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E2…
- CVE-2019-17341HIGHCVSS 7.8EG 7.82019-10-08
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
- CVE-2019-3744HIGHCVSS 7.8EG 7.82019-08-09
Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the install software packag…
- CVE-2018-16867HIGHCVSS 7.8EG 7.82018-12-12
A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-writ…
- CVE-2018-8897HIGHCVSS 7.8EG 7.82018-05-08
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB excep…
- CVE-2016-9038HIGHCVSS 7.8EG 7.82018-04-24
An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer and race condition can result in kernel memory corruption, which could result in privilege…
- CVE-2017-14880HIGHCVSS 7.8EG 7.82018-04-03
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while IPA WAN-driver is processing multiple requests from modem/user-space m…
- CVE-2018-7566HIGHCVSS 7.8EG 7.82018-03-30
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
- CVE-2017-15826HIGHCVSS 7.8EG 7.82018-03-30
Due to a race condition in MDSS rotator in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-20, a double free vulnerability may potentially exist when two threads free the same perf structures.
- CVE-2017-16512HIGHCVSS 7.8EG 7.82018-03-29
The vagrant update process in Hashicorp vagrant-vmware-fusion 5.0.2 through 5.0.4 allows local users to steal root privileges via a crafted update request when no updates are available.
- CVE-2018-5344HIGHCVSS 7.8EG 7.82018-01-12
In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (__lock_acquire use-after-free) or possibly have unspecified other impact.
- CVE-2017-16001HIGHCVSS 7.8EG 7.82017-11-06
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
- CVE-2017-15649HIGHCVSS 7.8EG 7.82017-10-19
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet…
- CVE-2017-15588HIGHCVSS 7.8EG 7.82017-10-18
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
- CVE-2017-9677HIGHCVSS 7.8EG 7.82017-09-21
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, while it is not protected with locks. If …
- CVE-2017-0794HIGHCVSS 7.8EG 7.82017-09-08
A elevation of privilege vulnerability in the Upstream kernel scsi driver. Product: Android. Versions: Android kernel. Android ID: A-35644812.
- CVE-2017-12136HIGHCVSS 7.8EG 7.82017-08-24
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free li…
- CVE-2017-8257HIGHCVSS 7.8EG 7.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, when accessing the sde_rotator debug interface for register reading with multiple processes, one process can free the debug buffer while another process still …
- CVE-2017-0727HIGHCVSS 7.8EG 7.82017-08-09
A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →