Security Advisory

CVE-2023-3514

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-07-14 04:53:31
Last updated 2024-11-05 19:56:27
Assigner STAR_Labs
State PUBLISHED

Description

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and calling "AddModule" or "UninstallModules" command to execute arbitrary executable file.