RSS   Vulnerabilities for 'Surround'   RSS

2019-07-09
 
CVE-2019-13142

CWE-264
 

 
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.

 

 >>> Vendor: Razer 2 Products
Synapse
Surround


Copyright 2024, cxsecurity.com

 

Back to Top