CVE-2021-44226

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:razer:synapse:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:30

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/166485/Razer-Synapse-3.6.x-DLL-Hijacking.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/166485/Razer-Synapse-3.6.x-DLL-Hijacking.html - Exploit, Third Party Advisory, VDB Entry
References () http://packetstormsecurity.com/files/170772/Razer-Synapse-3.7.0731.072516-Local-Privilege-Escalation.html - Not Applicable () http://packetstormsecurity.com/files/170772/Razer-Synapse-3.7.0731.072516-Local-Privilege-Escalation.html - Not Applicable
References () http://packetstormsecurity.com/files/174696/Razer-Synapse-Race-Condition-DLL-Hijacking.html - () http://packetstormsecurity.com/files/174696/Razer-Synapse-Race-Condition-DLL-Hijacking.html -
References () http://seclists.org/fulldisclosure/2022/Mar/51 - Exploit, Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2022/Mar/51 - Exploit, Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2023/Jan/26 - Not Applicable () http://seclists.org/fulldisclosure/2023/Jan/26 - Not Applicable
References () http://seclists.org/fulldisclosure/2023/Sep/6 - () http://seclists.org/fulldisclosure/2023/Sep/6 -
References () https://www.razer.com/community - Vendor Advisory () https://www.razer.com/community - Vendor Advisory
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-058.txt - Exploit, Third Party Advisory () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-058.txt - Exploit, Third Party Advisory

18 Sep 2023, 16:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/174696/Razer-Synapse-Race-Condition-DLL-Hijacking.html -
  • (FULLDISC) http://seclists.org/fulldisclosure/2023/Sep/6 -

Information

Published : 2022-03-23 22:15

Updated : 2024-11-21 06:30


NVD link : CVE-2021-44226

Mitre link : CVE-2021-44226

CVE.ORG link : CVE-2021-44226


JSON object : View

Products Affected

razer

  • synapse

microsoft

  • windows
CWE
CWE-427

Uncontrolled Search Path Element