Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/143516/Razer-Synapse-2.20-DLL-Hijacking.html | vdb entry third party advisory |