CVE-2021-30493
NixOS vulnerability analysis and mitigation

Overview

Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. The vulnerability affects Razer Synapse 3 version 3.5.1030.101917 and allows an attacker to create a file in an unintended directory with some limitations (VerSprite Advisory).

Technical details

The vulnerability stems from improper usage of the Windows Registry, where incorrect permission assignment leads to local users having full control over multiple important Registry keys relating to the Synapse 3 software suite. Local system services deployed via the Synapse 3 software suite utilize these Registry Keys to build file name paths to store runtime logging information. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The primary impact of this vulnerability is system instability and potential system denial of service (DoS) attacks. The vulnerability allows less privileged users to write files to any folder on disk, which can lead to system instability (VerSprite Research).

Exploitability

The vulnerability requires local access and low privileges to exploit. While the primary impact is denial of service, researchers note that full exploitation possibilities exist beyond the initial impact (VerSprite Research).

Mitigation and workarounds

Razer released initial updates to the Synapse 3 Software suite on February 25th, 2021, to address these vulnerabilities. However, subsequent verification revealed that the patch was only a partial solution, as the RzSDKService.exe service binary still interacted with a critical resource that had improper permissions assigned. Razer acknowledged the incomplete patch and committed to releasing a complete fix (VerSprite Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management