CyberRota Analysis
AI-GeneratedA vulnerability exists in Razer RzUpdateService 1.10.14.0, specifically within the Named Pipe Handler component, which allows for improper privilege management due to manipulation of the lpThreadParameter argument. This weakness requires local access to exploit, potentially enabling an attacker to escalate privileges on the affected system. Organizations using this software should prioritize patching to mitigate the risk of local attacks leveraging this exploit.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.