CVE-2019-13142: Medium severity razer surround vulnerability
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13142?
CVE-2019-13142 is a vulnerability in Razer Surround 1.1.63.0 that allows any user to overwrite contents of files in a specific folder.
What is the severity of CVE-2019-13142?
The severity of CVE-2019-13142 is medium, with a severity value of 5.5.
How does CVE-2019-13142 affect Razer Surround 1.1.63.0?
CVE-2019-13142 affects Razer Surround 1.1.63.0 by allowing any user to overwrite contents of files in a specific folder.
How can I fix CVE-2019-13142?
To fix CVE-2019-13142, you should update Razer Surround to a version that includes a patch for the vulnerability.
Where can I find more information about CVE-2019-13142?
You can find more information about CVE-2019-13142 at the following link: [https://posts.specterops.io/cve-2019-13142-razer-surround-1-1-63-0-eop-f18c52b8be0c]