Elevation of Privilege in Razer Surround by Razer Inc.
CVE-2019-13142
5.5MEDIUM
What is CVE-2019-13142?
The RzSurroundVADStreamingService.exe component within Razer Surround version 1.1.63.0 operates under the SYSTEM user context, allowing potential unauthorized user access. The incorrectly configured DACL on the executable's directory located at %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\ permits users to overwrite files within this folder, leading to possible exploitation and elevation of privileges. This vulnerability underscores the importance of proper permission settings for sensitive system components.
