Privilege Escalation Vulnerability in Razer Synapse by Razer
CVE-2022-47631
7.8HIGH
What is CVE-2022-47631?
Razer Synapse versions up to 3.7.1209.121307 are susceptible to a local privilege escalation due to improper privilege management and unsafe installation paths. An attacker can exploit this vulnerability by placing malicious DLLs in the service's directory before its installation. Although the service employs checks to prevent the execution of malicious DLLs, a race condition allows attackers to swap a legitimate DLL with a malicious version after initial verification. This flaw grants local Windows users the ability to elevate their privileges and potentially execute arbitrary code with administrative rights.
