top of page
perceptive_background_267k.jpg

A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to escalate privileges and ex…

Published:

1 April 2026 at 22:00:00

Alert date:

2 April 2026 at 17:03:11

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Security Tools

A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability affects Balena Etcher for Windows versions prior to v2.1.4. The vulnerability allows attackers to escalate privileges and execute arbitrary code by replacing legitimate scripts with malicious payloads during the flashing process. This represents a significant security risk as it can lead to complete system compromise. The vulnerability has been assigned CVE-2026-30332 and affects a popular disk imaging utility. Users should update to version 2.1.4 or later to mitigate this risk.

Technical details

Mitigation steps:

Affected products:

Balena Etcher

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page