Insecure DLL loading in Razer Synapse - CVE-2021-44226
Published: March 26, 2022
Razer Synapse
Razer
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads DLL libraries from the "C:\ProgramData\Razer\Synapse3\Service\bin" path. A local user can place a specially crafted .dll file into the aforementioned folder before Razer Synapse installation and escalate privileges on the system.