PT-2019-13150 · Razer · Razer Surround

Published

2019-07-09

·

Updated

2020-08-24

·

CVE-2019-13142

CVSS v2.0

6.6

Medium

VectorAV:L/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Razer Surround version 1.1.63.0
Description The issue concerns the RzSurroundVADStreamingService in Razer Surround, which runs as the SYSTEM user. It uses an executable located in a folder with a DACL that allows any user to overwrite the contents of files in this folder. This results in an Elevation of Privilege.
Recommendations For Razer Surround version 1.1.63.0, consider restricting access to the %PROGRAMDATA%RazerSynapseDevicesRazer SurroundDriver folder to prevent unauthorized overwriting of files until a patch is available.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13142

Affected Products

Razer Surround