CVE-2021-44226
CVE-2021-44226
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
23 Mar 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/166485/Razer-Synapse-3.6.x-DLL-Hijacking.htmlhttp://packetstormsecurity.com/files/170772/Razer-Synapse-3.7.0731.072516-Local-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/174696/Razer-Synapse-Race-Condition-DLL-Hijacking.htmlhttp://seclists.org/fulldisclosure/2022/Mar/51http://seclists.org/fulldisclosure/2023/Jan/26http://seclists.org/fulldisclosure/2023/Sep/6https://www.razer.com/communityhttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-058.txt