CVE-2025-9870: Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability
Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Philips HUE module installer. By creating a symbolic link, an attacker can abuse the installer to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-26375.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9870?
The severity of CVE-2025-9870 is classified as high due to the potential for local privilege escalation.
How do I fix CVE-2025-9870?
To fix CVE-2025-9870, update Razer Synapse 3 to the latest version provided by Razer.
Who is affected by CVE-2025-9870?
CVE-2025-9870 affects installations of Razer Synapse 3 on local systems.
What type of attacks can exploit CVE-2025-9870?
CVE-2025-9870 can be exploited by local attackers to escalate privileges on the affected system.
What is the nature of the vulnerability identified in CVE-2025-9870?
CVE-2025-9870 is a local privilege escalation vulnerability that involves improper handling of uninstall links.