
Cloud Vulnerability DB
A community-led vulnerabilities database
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. The vulnerability affects Razer Synapse 3 version 3.5.1030.101917 and allows an attacker to create a file in an unintended directory with some limitations (VerSprite Advisory).
The vulnerability stems from improper usage of the Windows Registry, where incorrect permission assignment leads to local users having full control over multiple important Registry keys relating to the Synapse 3 software suite. Local system services deployed via the Synapse 3 software suite utilize these Registry Keys to build file name paths to store runtime logging information. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).
The primary impact of this vulnerability is system instability and potential system denial of service (DoS) attacks. The vulnerability allows less privileged users to write files to any folder on disk, which can lead to system instability (VerSprite Research).
The vulnerability requires local access and low privileges to exploit. While the primary impact is denial of service, researchers note that full exploitation possibilities exist beyond the initial impact (VerSprite Research).
Razer released initial updates to the Synapse 3 Software suite on February 25th, 2021, to address these vulnerabilities. However, subsequent verification revealed that the patch was only a partial solution, as the RzSDKService.exe service binary still interacted with a critical resource that had improper permissions assigned. Razer acknowledged the incomplete patch and committed to releasing a complete fix (VerSprite Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."