Skip to content
Noroxi

Razer records

20 published records for vendor razer.

All records

20 records
  • CVE-2017-9769
    65This week

    A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a

    CriticalCVSS 9.8WeaponizedEPSS 86%

    razer · synapseAug 2, 2017

  • CVE-2022-29013
    62This week

    A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands

    CriticalCVSS 9.8Proof of conceptEPSS 77%

    razer · sila firmwareJun 8, 2022

  • A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.

    HighCVSS 7.5Proof of conceptEPSS 12%

    razer · sila firmwareJun 8, 2022

  • Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in whic

    HighCVSS 8.1Proof of conceptEPSS 6%

    razer · chroma sdkSep 2, 2020

  • Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges vi

    HighCVSS 8.4No exploitEPSS 0%

    razer · synapseAug 18, 2017

  • Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management.

    HighCVSS 7.8No exploitEPSS 0%

    razer · synapseSep 14, 2023

  • Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Tr

    HighCVSS 7.8No exploitEPSS 0%

    razer · synapseAug 18, 2017

  • CVE-2023-3513
    31Monitor

    RazerCentralService Unsafe Deserialization Escalation of Privilege

    HighCVSS 7.8No exploitEPSS 0%

    razer · razer centralJul 14, 2023

  • rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges

    HighCVSS 7.8No exploitEPSS 0%

    razer · synapseSep 13, 2017

  • Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.

    HighCVSS 7.8No exploitEPSS 0%

    razer · razer centralFeb 27, 2023

  • CVE-2023-3514
    31Monitor

    RazerCentralSerivce Unsafe Named Pipe Permission Escalation of Privilege Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    razer · razer centralJul 14, 2023

  • CVE-2025-9871
    31Monitor

    Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    razer · synapseOct 29, 2025

  • CVE-2025-9869
    31Monitor

    Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    razer · synapseOct 29, 2025

  • CVE-2025-9870
    31Monitor

    Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    razer · synapseOct 29, 2025

  • A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to esca

    HighCVSS 7.8No exploitEPSS 0%

    razer · synapse 4Jun 4, 2025

  • Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROG

    HighCVSS 7.3No exploitEPSS 1%

    razer · synapseMar 23, 2022

  • Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and impr

    MediumCVSS 6.8No exploitEPSS 1%

    razer · synapseJan 27, 2023

  • Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBr

    MediumCVSS 5.5No exploitEPSS 1%

    razer · synapseApr 14, 2021

  • Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Ch

    MediumCVSS 5.5No exploitEPSS 0%

    razer · synapseApr 14, 2021

  • The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable

    MediumCVSS 5.5No exploitEPSS 0%

    razer · surroundJul 9, 2019