VYPR
Unrated severityNVD Advisory· Published Jul 14, 2023· Updated Nov 5, 2024

RazerCentralSerivce Unsafe Named Pipe Permission Escalation of Privilege Vulnerability

CVE-2023-3514

Description

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and calling "AddModule" or "UninstallModules" command to execute arbitrary executable file.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.