Time-of-check Time-of-use (TOCTOU) Race Condition in QNAP Systems, Inc. products - CVE-2024-53694
Published: March 10, 2025
Vulnerability identifier: #VU105463
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-53694
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: QNAP Systems, Inc.
Affected software:
QVPN Device Client for Mac
Qsync Client for Mac
Qfinder Pro for Mac
QVPN Device Client for Mac
Qsync Client for Mac
Qfinder Pro for Mac
Detailed vulnerability description
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition. A local user can gain elevated privileges on the target system.
How to mitigate CVE-2024-53694
Install updates from vendor's website.