CVE-2022-47632: Medium severity razer synapse 3 vulnerability

Published Jan 27, 2023
·
Updated

Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can place malicious DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write access for the SYSTEM user. Although the service will not start if the malicious DLLs are unsigned, it suffices to use self-signed DLLs. The validity of the DLL signatures is not checked. As a result, local Windows users can abuse the Razer driver installer to obtain administrative privileges on Windows.

Affected Software

4 affected components
Razer Synapse<3.7.0830.081906
Microsoft Windows
All of the following
Razer Synapse<3.7.0830.081906
Microsoft Windows

Event History

Jan 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID of this Razer Synapse vulnerability?

The vulnerability ID of this Razer Synapse vulnerability is CVE-2022-47632.

2

What is the severity rating of CVE-2022-47632 vulnerability?

The severity rating of CVE-2022-47632 vulnerability is medium with a score of 6.8.

3

What is the impact of the Razer Synapse vulnerability?

The impact of the Razer Synapse vulnerability is privilege escalation.

4

How does CVE-2022-47632 vulnerability allow privilege escalation?

CVE-2022-47632 vulnerability allows privilege escalation by exploiting an unsafe installation path, improper privilege management, and improper certificate validation.

5

How can attackers exploit CVE-2022-47632 vulnerability?

Attackers can place malicious DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin before the service is installed, allowing them to escalate privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203