PT-2019-13150 · Razer · Razer Surround
Publicado
2019-07-09
·
Atualizado
2020-08-24
·
CVE-2019-13142
CVSS v2.0
6.6
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Razer Surround version 1.1.63.0
Description
The issue concerns the RzSurroundVADStreamingService in Razer Surround, which runs as the SYSTEM user. It uses an executable located in a folder with a DACL that allows any user to overwrite the contents of files in this folder. This results in an Elevation of Privilege.
Recommendations
For Razer Surround version 1.1.63.0, consider restricting access to the %PROGRAMDATA%RazerSynapseDevicesRazer SurroundDriver folder to prevent unauthorized overwriting of files until a patch is available.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Razer Surround