Razer Synapse Bug Gives Windows Admin Access to Anyone Who Can Plug in a Mouse

Razer Synapse Bug Gives Windows Admin Access to Anyone Who Can Plug in a Mouse

You might want to keep an eye on your USB ports for the next few days. A security researcher has disclosed a disturbingly easy way to gain admin privileges in Windows 10 without a password, and for once, it’s not Microsoft’s fault. This time, it’s all thanks to Razer and its Synapse software. A fix is in the works, but Razer missed the opportunity to head this one off before it was a problem.

The story starts with security researcher Jonhat (@j0nh4t on Twitter), who noticed that Razer’s Synapse software would deploy automatically whenever a Razer mouse or wireless receiver was plugged in. Like many feature-rich gaming peripherals, Razer requires the use of its desktop software to control lights, button mapping, and other features.

This part isn’t unusual — Windows Update automatically loads plenty of software for you based on attached hardware. It does this as System, but the current Razer Synapse installer retains System permissions, which turns out to be an issue.

According to Jonhat, it is possible to hijack the elevated Explorer process from the installation to open Powershell. From there, you can install anything you want because the System has the highest user rights available in Windows. In addition, as if that wasn’t bad enough, you can manually select a controllable installation path like Desktop. The installer creates a binary file that can be further leveraged to make any system changes persistent (the binary is executed even before login).

Need local admin and have physical access?– Plug a Razer mouse (or the dongle)– Windows Update will download and execute RazerInstaller as SYSTEM– Abuse elevated Explorer to open Powershell with Shift+Right click

Tried contacting @Razer, but no answers. So here's a freebie pic.twitter.com/xDkl87RCmz

— jonhat (@j0nh4t) August 21, 2021

With vulnerabilities of this severity, it’s expected that the discoverer will responsibly disclose by going through the company. However, Jonhat says Razer ignored his correspondence. So, he’s disclosed the zero-day bug publicly. Several others have since confirmed that a Razer mouse can help take over a Windows 10 PC in as little as a few minutes. Using this method, the attacker can install anything they want without logging in as an administrator.

So, that’s not a great situation, and the only saving grace is that someone needs physical access to your computer (and a Razer peripheral). Following the disclosure, Razer confirmed that it was working on a patch to be delivered soon. In the meantime, keep an eye out for lurkers with glowing mice.

Continue reading

AMD Roadmap Leak: Major Platform, Graphics Changes Coming in Zen 4
AMD Roadmap Leak: Major Platform, Graphics Changes Coming in Zen 4

Fresh rumors regarding AMD's long-term product roadmap have arisen and they imply some major improvements and changes coming with Zen 4.

Star Citizen Developer Unveils New Roadmap, Cancels Squadron 42 Beta
Star Citizen Developer Unveils New Roadmap, Cancels Squadron 42 Beta

Cloud Imperium Games has canceled the Squadron 42 beta that was supposed to debut before the end of 2020, with no current plan or timeline for launching it.

The Biden Administration Pledges to Address the Semiconductor Shortage
The Biden Administration Pledges to Address the Semiconductor Shortage

Early on Thursday, a group of US chip designers and manufacturers sent a letter to the White House, asking that the government include “substantial funding for incentives for semiconductor manufacturing” as part of the overall COVID-19 economic recovery plan. The Biden Administration has now pledged to take action to help remedy the situation by “identifying…

The US Air Force Quietly Admits the F-35 Is a Failure
The US Air Force Quietly Admits the F-35 Is a Failure

The Air Force has finally admitted that the F-35 is not the aircraft the military hoped it would be, though we doubt Ferrari would appreciate being compared with the F-35.