PT-2023-15444 · Razer · Razer Synapse
Dr. Oliver Schwarz
·
Published
2023-01-27
·
Updated
2025-03-28
·
CVE-2022-47632
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Razer Synapse versions prior to 3.7.0830.081906
Description
The issue arises due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can exploit this by placing malicious DLLs into
%PROGRAMDATA%RazerSynapse3Servicebin before the service is installed, and then denying write access for the SYSTEM user. Although the service will not start if the malicious DLLs are unsigned, using self-signed DLLs is sufficient for exploitation. The validity of the DLL signatures is not checked, allowing local Windows users to abuse the Razer driver installer to obtain administrative privileges on Windows.Recommendations
For versions prior to 3.7.0830.081906, update to version 3.7.0830.081906 or later to resolve the issue. As a temporary workaround, consider restricting access to the
%PROGRAMDATA%RazerSynapse3Servicebin directory to prevent malicious DLL placement. Additionally, ensure proper privilege management and certificate validation to minimize the risk of exploitation.Exploit
Fix
LPE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Razer Synapse