Rufus is a utility that helps format and create bootable USB flash drives. Versions 4.11 and below contain a race condition (TOCTOU) in src/net.c during the creation, validation, and execution of the Fido PowerShell script. Since Rufus runs with elevated privileges (Administrator) but writes the script to the %TEMP% directory (writeable by standard users) without locking the file, a local attacker can replace the legitimate script with a malicious one between the file write operation and the execution step. This allows arbitrary code execution with Administrator privileges. This issue has been fixed in version 4.12_BETA.
History

Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Pbatard
Pbatard rufus
Vendors & Products Pbatard
Pbatard rufus

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Rufus is a utility that helps format and create bootable USB flash drives. Versions 4.11 and below contain a race condition (TOCTOU) in src/net.c during the creation, validation, and execution of the Fido PowerShell script. Since Rufus runs with elevated privileges (Administrator) but writes the script to the %TEMP% directory (writeable by standard users) without locking the file, a local attacker can replace the legitimate script with a malicious one between the file write operation and the execution step. This allows arbitrary code execution with Administrator privileges. This issue has been fixed in version 4.12_BETA.
Title Rufus has Local Privilege Escalation via TOCTOU Race Condition in Fido Script Handling
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-01-22T21:52:26.925Z

Updated: 2026-01-22T21:52:26.925Z

Reserved: 2026-01-19T18:49:20.657Z

Link: CVE-2026-23988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-22T22:16:21.193

Modified: 2026-01-22T22:16:21.193

Link: CVE-2026-23988

cve-icon Redhat

No data.