Skip to main content

Vendor archive

razer CVEs

Beta · best-effort

20 CVEs tagged to vendor razer2 Critical, 14 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2025-9871

Published Oct 29, 2025

Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9870

Published Oct 29, 2025

Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected inst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9869

Published Oct 29, 2025

Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27811

Published Jun 4, 2025

A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate their privileges via a vulnerable…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-47631

Published Sep 14, 2023

Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLLs into %PROGRAMDATA%…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3514

Published Jul 14, 2023

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3513

Published Jul 14, 2023

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45697

Published Feb 27, 2023

Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-47632

Published Jan 27, 2023

Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29014

Published Jun 9, 2022

A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29013

Published Jun 9, 2022

A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-44226

Published Mar 23, 2022

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30494

Published Apr 14, 2021

Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged opera…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30493

Published Apr 14, 2021

Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16602

Published Sep 2, 2020

Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\R…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13142

Published Jul 9, 2019

The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14398

Published Sep 13, 2017

rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology involving a handle…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11653

Published Aug 18, 2017

Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) RazerConfigNative.dll or…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11652

Published Aug 18, 2017

Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9769

Published Aug 2, 2017

A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary pro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1