CVE-2021-44226

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
23/03/2022
Last modified:
18/09/2023

Description

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:razer:synapse:*:*:*:*:*:*:*:* 3.7.0228.022817 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*