CVE-2021-44226

HIGH

Razer Synapse < 3.7.0228.022817 - Uncontrolled Search Path Element via Service Bin Directory

Title source: llm
STIX 2.1

Description

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.

Scores

CVSS v3 7.3
EPSS 0.0089
EPSS Percentile 54.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
razer/synapse < 3.7.0228.022817
Published Mar 23, 2022
Tracked Since Feb 18, 2026