5.5

CVE-2021-30493

Exploit
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. In other words, an attacker can create a file in an unintended directory (with some limitations).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RazerSynapse Version3.5.1030.101917
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.397
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://versprite.com/advisories/razer-synapse-3-cve-2021-30493/
Third Party Advisory
https://versprite.com/blog/security-research/razer-synapse-3-security-vulnerability-analysis-report/
Third Party Advisory
Exploit
https://versprite.com/security-resources/
Third Party Advisory