Time-of-check Time-of-use (TOCTOU) Race Condition in QNAP Systems, Inc. products - CVE-2024-53694
Published: March 10, 2025
Vulnerability identifier: #VU105463
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-53694
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition. A local user can gain elevated privileges on the target system.
Affected software
QVPN Device Client for Mac
Qsync Client for Mac
Qfinder Pro for Mac
Qsync Client for Mac
Qfinder Pro for Mac
How to mitigate CVE-2024-53694
Install updates from vendor's website.
QVPN Device Client for Mac - update to 2.2.5
Qsync Client for Mac - update to 5.1.3
Qfinder Pro for Mac - update to 7.11.1
Qsync Client for Mac - update to 5.1.3
Qfinder Pro for Mac - update to 7.11.1