Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges via DLL hijacking.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://community.viveport.com/ | vendor advisory |
https://huskersec.com/privilege-escalation-via-htc-viveport-desktop-c93471ff87c8 | third party advisory exploit |
https://posts.specterops.io/razer-synapse-3-elevation-of-privilege-6d2802bd0585 | not applicable |