CVE-2021-30494: Medium severity razer synapse 3 vulnerability
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. In other words, an attacker can create a file in an unintended directory (with some limitations).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-30494?
CVE-2021-30494 is a vulnerability in the Razer Synapse 3 software suite that allows multiple system services to perform privileged operations on entries within the Razer Chroma SDK subkey.
How severe is CVE-2021-30494?
CVE-2021-30494 has a severity rating of medium, with a severity value of 5.5.
Which version of Razer Synapse is affected by CVE-2021-30494?
Razer Synapse version 3.5.1030.101917 is affected by CVE-2021-30494.
Are there any references for CVE-2021-30494?
Yes, you can find references for CVE-2021-30494 at the following links: [Reference 1](https://versprite.com/advisories/razer-synapse-3-1/), [Reference 2](https://versprite.com/blog/security-research/razer-synapse-3-security-vulnerability-analysis-report/), [Reference 3](https://versprite.com/security-resources/).
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-30494?
The Common Weakness Enumeration (CWE) ID for CVE-2021-30494 is CWE-276.