CVE-2021-44226

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:razer:synapse:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-03-23 22:15

Updated : 2023-09-18 16:15


NVD link : CVE-2021-44226

Mitre link : CVE-2021-44226

CVE.ORG link : CVE-2021-44226


JSON object : View

Products Affected

razer

  • synapse

microsoft

  • windows
CWE
CWE-427

Uncontrolled Search Path Element