CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A security researcher finds that a file-permission-checking function in an application checks whether a user has access to a file, but a brief delay occurs before the file is actually opened. An attacker exploits this delay by swapping the file with a symbolic link to a sensitive file after the check but before the open. Which vulnerability class does this represent?

  1. ABuffer overflow
  2. BCross-site request forgery
  3. CInsecure direct object reference
  4. DTime-of-check to time-of-use (TOCTOU) race condition
Show answer & explanation

Correct answer: D. Time-of-check to time-of-use (TOCTOU) race condition

Exploiting the gap between when a resource is checked and when it is used, by swapping the resource in that window, is the defining characteristic of a TOCTOU race condition.

Why the other options are wrong

  • A. Buffer overflow involves memory bounds, not timing between check and use.
  • B. CSRF exploits authenticated sessions to force actions, unrelated to timing gaps in file access.
  • C. IDOR involves referencing objects directly without authorization checks, not a timing race.

TOCTOU Race Condition

A vulnerability where a resource's state changes between the time it is checked and the time it is used, allowing an attacker to substitute a different resource.

  • Common in file-system operations
  • Also called a 'check-then-act' flaw
  • Mitigated by atomic operations or file locking

Memory trick: Check now, swap fast, use later — the race is won in the gap.

More Threats, Vulnerabilities, and Mitigations questions