Razer / Synapse
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-9870 | Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability | HIGH | 7.8 | Oct 29, 2025 |
| CVE-2025-9871 | Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability | HIGH | 7.8 | Oct 29, 2025 |
| CVE-2025-9869 | Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability | HIGH | 7.8 | Oct 29, 2025 |
| CVE-2022-47631 | Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLL… | HIGH | 7.8 | Sep 14, 2023 |
| CVE-2022-47632 | Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate va… | MEDIUM | 6.8 | Jan 27, 2023 |
| CVE-2021-44226 | Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has… | HIGH | 7.3 | Mar 23, 2022 |
| CVE-2021-30494 | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. Th… | MEDIUM | 5.5 | Apr 14, 2021 |
| CVE-2021-30493 | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. The… | MEDIUM | 5.5 | Apr 14, 2021 |
| CVE-2017-14398 | rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology… | HIGH | 7.8 | Sep 13, 2017 |
| CVE-2017-11653 | Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) Raze… | HIGH | 7.8 | Aug 18, 2017 |
| CVE-2017-11652 | Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse db… | HIGH | 8.4 | Aug 18, 2017 |
| CVE-2017-9769 | A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened… | CRITICAL | 9.8 | Aug 2, 2017 |
Showing 1 to 12 of 12 CVEs