CVE-2017-9769: Critical severity razer synapse 3 vulnerability
Published Aug 2, 2017
·Updated
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.
Affected Software
1 affected component
Razer Synapse=2.20.15.1104
Event History
Aug 2, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9769?
CVE-2017-9769 has been assigned a medium severity rating due to the potential for privilege escalation.
2
How do I fix CVE-2017-9769?
To mitigate CVE-2017-9769, update Razer Synapse to the latest version provided by Razer.
3
What is the affected software for CVE-2017-9769?
CVE-2017-9769 specifically affects Razer Synapse version 2.20.15.1104.
4
What type of vulnerability is CVE-2017-9769?
CVE-2017-9769 is a local privilege escalation vulnerability affecting the rzpnk.sys driver.
5
Can CVE-2017-9769 be exploited remotely?
No, CVE-2017-9769 requires local access to exploit the vulnerability.