


Perceptive Security
SOC/SIEM Consultancy

A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to escalate privileges and ex…
Published:
1 april 2026 om 22:00:00
Alert date:
2 april 2026 om 17:03:11
Source:
nvd.nist.gov
Operating Systems, Security Tools
A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability affects Balena Etcher for Windows versions prior to v2.1.4. The vulnerability allows attackers to escalate privileges and execute arbitrary code by replacing legitimate scripts with malicious payloads during the flashing process. This represents a significant security risk as it can lead to complete system compromise. The vulnerability has been assigned CVE-2026-30332 and affects a popular disk imaging utility. Users should update to version 2.1.4 or later to mitigate this risk.
Technical details
Mitigation steps:
Affected products:
Balena Etcher
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30332
https://github.com/B1tBreaker/CVE-2026-30332
https://github.com/balena-io/etcher/issues/4500
https://www.balena.io/security
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
