packetstormsecurity.com
http://packetstormsecurity.com/files/160225/Razer-Chroma-SDK-Server-3.16.02-Race-Condition.html CVE-2020-16602
HIGH
Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
Record summary
CVE-2020-16602 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit.
Description
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have access to port 54236 for a registration step.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRazer Chroma SDK Server 3.16.02 - Race Condition Remote File ExecutionExploitDB exploitby Loke Hui YiNot analyzed1 file
References
5assets.razerzone.com
https://assets.razerzone.com/dev_portal/REST/html/index.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-16602 angelystor.com
https://www.angelystor.com/2020/09/cve-2020-16602-remote-file-execution-on.html youtube.com
https://www.youtube.com/watch?v=fkESBVhIdIA