Zero-day vulnerability (Aug21) been fixed? | Razer Insider

Zero-day vulnerability (Aug21) been fixed?

  • 17 January 2022
  • 4 replies
  • 135 views

Has the zero-day vulnerability that was identified in August 2021 been fixed? I would really like to run Synapse but have been advised against it. Could someone please let me know if it has been fixed?

This topic has been closed for comments

4 Replies

Userlevel 7
csggdan
Has the zero-day vulnerability that was identified in August 2021 been fixed? I would really like to run Synapse but have been advised against it. Could someone please let me know if it has been fixed?

Hi @csggdan,
Since it's listed as local privilege escalation (LPE) vulnerability, which means that you need to have a Razer devices and physical access to a computer.
Unless you're installing the software on a shared computer, it should be fine for user unless your home screen is not locked with any password at all.

As for that status for the vuln, might have to wait the staff for official reply or you can simulate the vuln based on the POC posted by the researcher.
OK - unfortunately it is a shared PC where any user should not have admin privilege. Will reach out to official channel to see if there is a definitive answer on fix. Thank you.
@csggdan did you get any answer regarding this?
Unfortunately our IT administrators deemed the risk to high to allow network installs with any Razer equipment. We instead sourced our Esports equipment with another vendor which we are very happy with.