CVE-2021-44226
HIGHRazer Synapse < 3.7.0228.022817 - Uncontrolled Search Path
Title source: ruleDescription
Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.
References (8)
Scores
CVSS v3
7.3
EPSS
0.0006
EPSS Percentile
19.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
razer/synapse
< 3.7.0228.022817
Timeline
Published
Mar 23, 2022
Tracked Since
Feb 18, 2026