Vulnerability CVE-2020-16602


Published: 2020-09-02

Description:
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have access to port 54236 for a registration step.

See advisories in our WLB2 database:
Topic
Author
Date
High
Razer Chroma SDK Server 3.16.02 Race Condition Remote File Execution
Loke Hui Yi
26.11.2020

Type:

CWE-362

 References:
https://assets.razerzone.com/dev_portal/REST/html/index.html
https://www.youtube.com/watch?v=fkESBVhIdIA

Copyright 2024, cxsecurity.com

 

Back to Top