Dad On Retire
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Email Whitelisting
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
Dad On Retire
No Result
View All Result
Home Editor's Pick

Need to get root on a Windows box? Plug in a Razer gaming mouse

by
August 26, 2021
in Editor's Pick
0
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter

Enlarge (credit: Razer)

This weekend, security researcher jonhat disclosed a long-standing security bug in the Synapse software associated with Razer gaming mice. During software installation, the wizard produces a clickable link to the location where the software will be installed. Clicking that link opens a File Explorer window to the proposed location—but that File Explorer spawns with SYSTEM process ID, not with the user’s.

Have mouse, will root

The “Install Location” at the lower right is a clickable link that opens a File Explorer window to browse for non-standard locations. [credit:
jonhat
]

By itself, this vulnerability in Razer Synapse sounds like a minor issue—after all, in order to launch a software installer with SYSTEM privileges, a user would normally need to have Administrator privileges themselves. Unfortunately, Synapse is a part of the Windows Catalog—which means that an unprivileged user can just plug in a Razer mouse, and Windows Update will cheerfully download and run the exploitable installer automatically.

Jonhat isn’t the only—or even the first—researcher to discover and publicly disclose this bug. Lee Christensen publicly disclosed the same bug in July, and according to security researcher _MG_, who demonstrated it using an OMG cable to mimic the PCI Device ID of a Razer mouse and exploit the same vulnerability, researchers have been reporting it fruitlessly for more than a year.

Read 2 remaining paragraphs | Comments

Previous Post

Nude hunt: LA phisherman accessed 4,700 iCloud accounts, 620K photos

Next Post

“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

Next Post

“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

Get the daily email that makes reading the news actually enjoyable. Stay informed and entertained, for free.
Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!
  • Trending
  • Comments
  • Latest

VPN servers seized by Ukrainian authorities weren’t encrypted

July 26, 2021

With help from Google, impersonated Brave.com website pushes malware

July 31, 2021

Prebiotics consumption expands in food and beverage applications – key nutritional benefits drive the ingredient demand

June 11, 2021

With help from Google, impersonated Brave.com website pushes malware

July 31, 2021

The 40 Weirdest (And Best) Charts We Made In This Long, Strange Year

0

How U.S. Government Paper Currency Began, and How Private Banknotes Ended

0

Covid Inside Rural India

0

Reply to “Reply to Whitehead” by Desvousges, Mathews and Train: (4) My treatment of the weighted WTP is biased in favor of the DMT (2015) result/conclusion

0
Biden announces new northern border deal, fentanyl coalition with Canada as immigration crisis rages

Biden announces new northern border deal, fentanyl coalition with Canada as immigration crisis rages

March 25, 2023
Pence touts fighter pilot son in jab at Hunter Biden probe: ‘can’t really relate’

Pence touts fighter pilot son in jab at Hunter Biden probe: ‘can’t really relate’

March 25, 2023
Nancy Pelosi calls out San Francisco archbishop who barred her from communion: ‘His problem, not mine’

Nancy Pelosi calls out San Francisco archbishop who barred her from communion: ‘His problem, not mine’

March 25, 2023
Florida one step closer to giving DeSantis chance to make US a constitutional carry majority

Florida one step closer to giving DeSantis chance to make US a constitutional carry majority

March 25, 2023

Recent News

Biden announces new northern border deal, fentanyl coalition with Canada as immigration crisis rages

Biden announces new northern border deal, fentanyl coalition with Canada as immigration crisis rages

March 25, 2023
Pence touts fighter pilot son in jab at Hunter Biden probe: ‘can’t really relate’

Pence touts fighter pilot son in jab at Hunter Biden probe: ‘can’t really relate’

March 25, 2023
Nancy Pelosi calls out San Francisco archbishop who barred her from communion: ‘His problem, not mine’

Nancy Pelosi calls out San Francisco archbishop who barred her from communion: ‘His problem, not mine’

March 25, 2023
Florida one step closer to giving DeSantis chance to make US a constitutional carry majority

Florida one step closer to giving DeSantis chance to make US a constitutional carry majority

March 25, 2023

Disclaimer: DadOnRetire.com, its managers, its employees, and assigns (collectively "The Company") do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Email Whitelisting

Copyright © 2022 DadOnRetire. All Rights Reserved.

No Result
View All Result
  • Economy
  • Editor’s Pick
  • Investing
  • Stock

Copyright © 2022 DadOnRetire. All Rights Reserved.