CVE-2021-44226

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:razer:synapse:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

18 Sep 2023, 16:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/174696/Razer-Synapse-Race-Condition-DLL-Hijacking.html -
  • (FULLDISC) http://seclists.org/fulldisclosure/2023/Sep/6 -

Information

Published : 2022-03-23 22:15

Updated : 2024-02-28 19:09


NVD link : CVE-2021-44226

Mitre link : CVE-2021-44226

CVE.ORG link : CVE-2021-44226


JSON object : View

Products Affected

razer

  • synapse

microsoft

  • windows
CWE
CWE-427

Uncontrolled Search Path Element