10

CVE-2017-9769

Exploit
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RazerSynapse Version2.20.15.1104
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 85.54% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.rapid7.com/db/modules/exploit/windows/local/razer_zwopenprocess
Third Party Advisory
Exploit
https://warroom.securestate.com/cve-2017-9769/
Third Party Advisory
Exploit
https://www.exploit-db.com/exploits/42368/
Third Party Advisory
VDB Entry