Vulnerability Description
rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology involving a handle to \Device\PhysicalMemory, IOCTL 0x22A064, and ZwMapViewOfSection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Razer | Synapse | 2.20.15.1104 |
Related Weaknesses (CWE)
References
- https://twitter.com/FuzzySec/status/907722788219256832Third Party Advisory
- https://twitter.com/FuzzySec/status/907722788219256832Third Party Advisory
FAQ
What is CVE-2017-14398?
CVE-2017-14398 is a vulnerability with a CVSS score of 7.8 (HIGH). rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology involving a handle to \Device\PhysicalMe...
How severe is CVE-2017-14398?
CVE-2017-14398 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14398?
Check the references section above for vendor advisories and patch information. Affected products include: Razer Synapse.