CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 20 of 55
- CVE-2025-39966HIGHCVSS 7.0EG 7.02025-10-15
In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix race during abort for file descriptors fput() doesn't actually call file_operations release() synchronously, it puts the file on a work queue and it will be…
- CVE-2025-59282HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- CVE-2025-59205HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2025-59196HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-59195HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
- CVE-2025-59193HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2025-58727HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
- CVE-2023-53622HIGHCVSS 7.0EG 7.02025-10-07
In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix possible data races in gfs2_show_options() Some fields such as gt_logd_secs of the struct gfs2_tune are accessed without holding the lock gt_spin in gfs2_show_…
- CVE-2025-39905HIGHCVSS 7.0EG 7.02025-10-01
In the Linux kernel, the following vulnerability has been resolved: net: phylink: add lock for serializing concurrent pl->phydev writes with resolver Currently phylink_resolve() protects itself against concurrent phylink_bringup_phy() or…
- CVE-2025-59220HIGHCVSS 7.0EG 7.02025-09-18
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-59216HIGHCVSS 7.0EG 7.02025-09-18
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2022-50339HIGHCVSS 7.0EG 7.02025-09-16
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: avoid hci_dev_test_and_set_flag() in mgmt_init_hdev() syzbot is again reporting attempt to cancel uninitialized work at mgmt_index_removed() [1], for setting …
- CVE-2025-43304HIGHCVSS 7.0EG 7.02025-09-15
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to gain root privileges.
- CVE-2025-39759HIGHCVSS 7.0EG 7.02025-09-11
In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix race between quota disable and quota rescan ioctl There's a race between a task disabling quotas and another running the rescan ioctl that can result …
- CVE-2025-55223HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-54115HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-54114HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-54108HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- CVE-2025-54105HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2025-53807HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2025-48533HIGHCVSS 7.0EG 7.02025-09-04
In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…
- CVE-2025-22442HIGHCVSS 7.0EG 7.02025-09-02
In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created work profile due to a race condition. This could lead to local escalation of privilege with no addi…
- CVE-2025-53135HIGHCVSS 7.0EG 7.02025-08-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.
- CVE-2025-50167HIGHCVSS 7.0EG 7.02025-08-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-49762HIGHCVSS 7.0EG 7.02025-08-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-47907HIGHCVSS 7.0EG 7.02025-08-07
Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a…
- CVE-2025-49744HIGHCVSS 7.0EG 7.02025-07-08
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2025-49737HIGHCVSS 7.0EG 7.02025-07-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
- CVE-2025-49678HIGHCVSS 7.0EG 7.02025-07-08
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2025-38108HIGHCVSS 7.0EG 7.02025-07-03
In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerrard Tai reported a race condition in RED, whenever SFQ perturb timer fires at the wrong time. The race is as follows: …
- CVE-2025-38107HIGHCVSS 7.0EG 7.02025-07-03
In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: fix a race in ets_qdisc_change() Gerrard Tai reported a race condition in ETS, whenever SFQ perturb timer fires at the wrong time. The race is as follow…
- CVE-2025-38102HIGHCVSS 7.0EG 7.02025-07-03
In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify During our test, it is found that a warning can be trigger in try_grab_folio as follow: ------…
- CVE-2022-50082HIGHCVSS 7.0EG 7.02025-06-18
In the Linux kernel, the following vulnerability has been resolved: ext4: fix warning in ext4_iomap_begin as race between bmap and write We got issue as follows: ------------[ cut here ]------------ WARNING: CPU: 3 PID: 9310 at fs/ext4/i…
- CVE-2022-50014HIGHCVSS 7.0EG 7.02025-06-18
In the Linux kernel, the following vulnerability has been resolved: mm/gup: fix FOLL_FORCE COW security issue and remove FOLL_COW Ever since the Dirty COW (CVE-2016-5195) security issue happened, we know that FOLL_FORCE can be possibly d…
- CVE-2022-49939HIGHCVSS 7.0EG 7.02025-06-18
In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF of ref->proc caused by race condition A transaction of type BINDER_TYPE_WEAK_HANDLE can fail to increment the reference for a node. In this case, the tar…
- CVE-2025-29841HIGHCVSS 7.0EG 7.02025-05-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-27468HIGHCVSS 7.0EG 7.02025-05-13
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
- CVE-2022-49919HIGHCVSS 7.0EG 7.02025-05-01
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flow rule object from commit path No need to postpone this to the commit release path, since no packets are walking over this object, this …
- CVE-2025-22036HIGHCVSS 7.0EG 7.02025-04-16
In the Linux kernel, the following vulnerability has been resolved: exfat: fix random stack corruption after get_block When get_block is called with a buffer_head allocated on the stack, such as do_mpage_readpage, stack corruption due to…
- CVE-2025-27492HIGHCVSS 7.0EG 7.02025-04-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
- CVE-2025-26649HIGHCVSS 7.0EG 7.02025-04-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
- CVE-2025-21718HIGHCVSS 7.0EG 7.02025-02-27
In the Linux kernel, the following vulnerability has been resolved: net: rose: fix timer races against user threads Rose timers only acquire the socket spinlock, without checking if the socket is owned by one user thread. Add a check an…
- CVE-2024-49724HIGHCVSS 7.0EG 7.02025-01-21
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privi…
- CVE-2018-9461HIGHCVSS 7.0EG 7.02025-01-18
In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed.…
- CVE-2024-57876HIGHCVSS 7.0EG 7.02025-01-11
In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Fix resetting msg rx state after topology removal If the MST topology is removed during the reception of an MST down reply or MST up request sideband message…
- CVE-2024-56664HIGHCVSS 7.0EG 7.02024-12-27
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix race between element replace and close() Element replace (with a socket different from the one stored) may race with socket's close() link popping & un…
- CVE-2024-56635HIGHCVSS 7.0EG 7.02024-12-27
In the Linux kernel, the following vulnerability has been resolved: net: avoid potential UAF in default_operstate() syzbot reported an UAF in default_operstate() [1] Issue is a race between device and netns dismantles. After calling __…
- CVE-2024-56556HIGHCVSS 7.0EG 7.02024-12-27
In the Linux kernel, the following vulnerability has been resolved: binder: fix node UAF in binder_add_freeze_work() In binder_add_freeze_work() we iterate over the proc->nodes with the proc->inner_lock held. However, this lock is tempor…
- CVE-2024-53186HIGHCVSS 7.0EG 7.02024-12-27
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in SMB request handling A race condition exists between SMB request handling in `ksmbd_conn_handler_loop()` and the freeing of `ksmbd_conn` in …
- CVE-2024-49097HIGHCVSS 7.0EG 7.02024-12-12
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →