A time-of-check time-of-use (TOCTOU) race condition...
High severity
Unreviewed
Published
Mar 7, 2025
to the GitHub Advisory Database
•
Updated Mar 7, 2025
Description
Published by the National Vulnerability Database
Mar 7, 2025
Published to the GitHub Advisory Database
Mar 7, 2025
Last updated
Mar 7, 2025
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.
We have already fixed the vulnerability in the following versions:
QVPN Device Client for Mac 2.2.5 and later
Qsync for Mac 5.1.3 and later
Qfinder Pro Mac 7.11.1 and later
References