Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-98w8-8hm2-7f2j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.

The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.

EPSS

Процентиль: 13%
0.00042
Низкий

Связанные уязвимости

CVSS3: 5.5
nvd
больше 6 лет назад

The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.

EPSS

Процентиль: 13%
0.00042
Низкий