PT-2023-15444 · Razer · Razer Synapse

Dr. Oliver Schwarz

·

Published

2023-01-27

·

Updated

2025-03-28

·

CVE-2022-47632

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Razer Synapse versions prior to 3.7.0830.081906
Description The issue arises due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can exploit this by placing malicious DLLs into %PROGRAMDATA%RazerSynapse3Servicebin before the service is installed, and then denying write access for the SYSTEM user. Although the service will not start if the malicious DLLs are unsigned, using self-signed DLLs is sufficient for exploitation. The validity of the DLL signatures is not checked, allowing local Windows users to abuse the Razer driver installer to obtain administrative privileges on Windows.
Recommendations For versions prior to 3.7.0830.081906, update to version 3.7.0830.081906 or later to resolve the issue. As a temporary workaround, consider restricting access to the %PROGRAMDATA%RazerSynapse3Servicebin directory to prevent malicious DLL placement. Additionally, ensure proper privilege management and certificate validation to minimize the risk of exploitation.

Exploit

Fix

LPE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-47632

Affected Products

Razer Synapse