CVE-2017-11653: High severity razer synapse 3 vulnerability
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) RazerConfigNative.dll or (2) RazerConfigNativeLOC.dll file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11653?
CVE-2017-11653 has a medium severity rating due to the local privilege escalation that it allows.
How do I fix CVE-2017-11653?
To fix CVE-2017-11653, update Razer Synapse to version 2.20.15.1105 or later, which addresses the permission issue.
What type of vulnerability is CVE-2017-11653?
CVE-2017-11653 is a local privilege escalation vulnerability caused by weak permissions in the Devices directory.
Who is affected by CVE-2017-11653?
Local users of Razer Synapse versions 2.20.15.1104 and earlier are affected by CVE-2017-11653.
What can attackers exploit in CVE-2017-11653?
Attackers can exploit CVE-2017-11653 by placing a malicious RazerConfigNative.dll or RazerConfigNativeLOC.dll file in the Devices directory.