Vulnerability Description
Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Razer | Synapse | < 3.7.0228.022817 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/166485/Razer-Synapse-3.6.x-DLL-Hijacking.htExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/170772/Razer-Synapse-3.7.0731.072516-Local-Not Applicable
- http://packetstormsecurity.com/files/174696/Razer-Synapse-Race-Condition-DLL-Hij
- http://seclists.org/fulldisclosure/2022/Mar/51ExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2023/Jan/26Not Applicable
- http://seclists.org/fulldisclosure/2023/Sep/6
- https://www.razer.com/communityVendor Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-058.tExploitThird Party Advisory
- http://packetstormsecurity.com/files/166485/Razer-Synapse-3.6.x-DLL-Hijacking.htExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/170772/Razer-Synapse-3.7.0731.072516-Local-Not Applicable
- http://packetstormsecurity.com/files/174696/Razer-Synapse-Race-Condition-DLL-Hij
- http://seclists.org/fulldisclosure/2022/Mar/51ExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2023/Jan/26Not Applicable
- http://seclists.org/fulldisclosure/2023/Sep/6
- https://www.razer.com/communityVendor Advisory
FAQ
What is CVE-2021-44226?
CVE-2021-44226 is a vulnerability with a CVSS score of 7.3 (HIGH). Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user bef...
How severe is CVE-2021-44226?
CVE-2021-44226 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44226?
Check the references section above for vendor advisories and patch information. Affected products include: Razer Synapse, Microsoft Windows.