PT-2022-12023 · Razer · Razer Synapse

Dr. Oliver Schwarz

+1

·

Published

2022-03-23

·

Updated

2023-09-18

·

CVE-2021-44226

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Razer Synapse versions prior to 3.7.0228.022817
Description The issue allows privilege escalation because Razer Synapse relies on %PROGRAMDATA%RazerSynapse3Servicebin even if %PROGRAMDATA%Razer has been created by any unprivileged user before Synapse is installed. An unprivileged user may have placed Trojan horse DLLs there.
Recommendations For versions prior to 3.7.0228.022817, update to version 3.7.0228.022817 or later to resolve the issue. As a temporary workaround, consider restricting access to the %PROGRAMDATA%RazerSynapse3Servicebin directory to prevent potential exploitation.

Exploit

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2021-44226

Affected Products

Razer Synapse