ZDI-25-920: Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Razer Chroma SDK installer. By creating a symbolic link, an attacker can abuse the installer to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-9871.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-920?
ZDI-25-920 has a CVSS rating of 7, indicating a high severity level.
How do I fix ZDI-25-920?
To fix ZDI-25-920, update to the latest version of Razer Synapse 3 provided by Razer.
Who is affected by ZDI-25-920?
ZDI-25-920 affects installations of Razer Synapse 3 on systems where local attackers can execute low-privileged code.
What type of attack does ZDI-25-920 enable?
ZDI-25-920 enables local privilege escalation attacks on affected installations.
Is it necessary to have prior access to exploit ZDI-25-920?
Yes, an attacker must first gain the ability to execute low-privileged code to exploit ZDI-25-920.