CVE-2017-9770: Medium severity razer synapse 3 vulnerability
Published Aug 2, 2017
·Updated
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse that can cause an out of bounds read operation to occur due to a field within the IOCTL data being used as a length.
Affected Software
1 affected component
razerzone Razer Synapse
Event History
Aug 2, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9770?
CVE-2017-9770 is rated as a high severity vulnerability due to its potential to cause an out of bounds read operation.
2
What software is affected by CVE-2017-9770?
CVE-2017-9770 affects Razer Synapse, specifically version 3.
3
How do I fix CVE-2017-9770?
To fix CVE-2017-9770, update Razer Synapse to the latest version provided by Razer.
4
What causes CVE-2017-9770?
CVE-2017-9770 is caused by a specially crafted IOCTL being sent to the rzpnk.sys driver.
5
Is CVE-2017-9770 a remote attack vulnerability?
CVE-2017-9770 requires local access to the system to exploit, making it less of a remote attack vulnerability.