CVE-2017-11652: High severity razer synapse 3 vulnerability
Published Aug 18, 2017
·Updated
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file.
Affected Software
1 affected component
Razer Synapse<=2.20.15.1104
Event History
Aug 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11652?
CVE-2017-11652 is rated as a medium severity vulnerability due to its potential to allow privilege escalation.
2
How do I fix CVE-2017-11652?
To fix CVE-2017-11652, update Razer Synapse to a version later than 2.20.15.1104 to ensure proper permissions for the CrashReporter directory.
3
What type of vulnerability is CVE-2017-11652?
CVE-2017-11652 is a DLL hijacking vulnerability that exploits weak directory permissions for local privilege escalation.
4
Who is affected by CVE-2017-11652?
Users of Razer Synapse versions up to and including 2.20.15.1104 are affected by CVE-2017-11652.
5
Can CVE-2017-11652 be exploited remotely?
No, CVE-2017-11652 requires local access to the system to exploit the vulnerability.