Vulnerability Description
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have access to port 54236 for a registration step.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Razer | Chroma Sdk | <= 3.12.17 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/160225/Razer-Chroma-SDK-Server-3.16.02-RaceExploitThird Party AdvisoryVDB Entry
- https://assets.razerzone.com/dev_portal/REST/html/index.htmlVendor Advisory
- https://www.angelystor.com/2020/09/cve-2020-16602-remote-file-execution-on.htmlThird Party Advisory
- https://www.youtube.com/watch?v=fkESBVhIdIAThird Party Advisory
- http://packetstormsecurity.com/files/160225/Razer-Chroma-SDK-Server-3.16.02-RaceExploitThird Party AdvisoryVDB Entry
- https://assets.razerzone.com/dev_portal/REST/html/index.htmlVendor Advisory
- https://www.angelystor.com/2020/09/cve-2020-16602-remote-file-execution-on.htmlThird Party Advisory
- https://www.youtube.com/watch?v=fkESBVhIdIAThird Party Advisory
FAQ
What is CVE-2020-16602?
CVE-2020-16602 is a vulnerability with a CVSS score of 8.1 (HIGH). Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps"...
How severe is CVE-2020-16602?
CVE-2020-16602 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16602?
Check the references section above for vendor advisories and patch information. Affected products include: Razer Chroma Sdk.