ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Interesting Privilege Escalation Vulnerability

criticalVulnerabilityimportance 55
Full article123 words · extracted from schneier.com · click to collapse

If you plug a Razer peripheral (mouse or keyboard, I think) into a Windows 10 or 11 machine, you can use a vulnerability in the Razer Synapse software—which automatically downloads—to gain SYSTEM privileges.

It should be noted that this is a local privilege escalation (LPE) vulnerability, which means that you need to have a Razer devices and physical access to a computer. With that said, the bug is so easy to exploit as you just need to spend $20 on Amazon for Razer mouse and plug it into Windows 10 to become an admin.

Tags: privilege escalation, vulnerabilities, Windows, zero-day

Posted on August 26, 2021 at 6:28 AM12 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/08/interesting-privilege-escalation-vulnerability.html