PT-2022-12023 · Razer · Razer Synapse
Dr. Oliver Schwarz
+1
·
Published
2022-03-23
·
Updated
2023-09-18
·
CVE-2021-44226
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Razer Synapse versions prior to 3.7.0228.022817
Description
The issue allows privilege escalation because Razer Synapse relies on
%PROGRAMDATA%RazerSynapse3Servicebin even if %PROGRAMDATA%Razer has been created by any unprivileged user before Synapse is installed. An unprivileged user may have placed Trojan horse DLLs there.Recommendations
For versions prior to 3.7.0228.022817, update to version 3.7.0228.022817 or later to resolve the issue. As a temporary workaround, consider restricting access to the
%PROGRAMDATA%RazerSynapse3Servicebin directory to prevent potential exploitation.Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Razer Synapse