Vulnerability Description
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Razer | Surround | 1.1.63.0 |
Related Weaknesses (CWE)
References
- https://posts.specterops.io/cve-2019-13142-razer-surround-1-1-63-0-eop-f18c52b8bThird Party Advisory
- https://posts.specterops.io/cve-2019-13142-razer-surround-1-1-63-0-eop-f18c52b8bThird Party Advisory
FAQ
What is CVE-2019-13142?
CVE-2019-13142 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surrou...
How severe is CVE-2019-13142?
CVE-2019-13142 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13142?
Check the references section above for vendor advisories and patch information. Affected products include: Razer Surround.