Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies...
Vulnerability Description
Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-44226
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.razer.com/community
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-058.txt
- http://seclists.org/fulldisclosure/2022/Mar/51
- http://packetstormsecurity.com/files/166485/Razer-Synapse-3.6.x-DLL-Hijacking.html
- http://seclists.org/fulldisclosure/2023/Jan/26
- http://packetstormsecurity.com/files/170772/Razer-Synapse-3.7.0731.072516-Local-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2023/Sep/6
- http://packetstormsecurity.com/files/174696/Razer-Synapse-Race-Condition-DLL-Hijacking.html
More from razer
View All →Affected Vendor
razer
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.