Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Tech News
  • Contact
  • Toggle search form

Administrative rights gained through Razer devices on Windows 10

Posted on 25/08/202120/08/2026 IT Expert By IT Expert No Comments on Administrative rights gained through Razer devices on Windows 10
  1. Home
  2. Security | Vulnerability Scans and Assessment
  3. Administrative rights gained through Razer devices on Windows 10
Razer

A Razer Synapse is a software that allows users to configure their hardware devices, set up macros, or map buttons. Recently, security researchers uncovered a zero-day vulnerability in Razer devices. This vulnerability allowed attackers to gain Windows administrative rights gained through Razer devices like mouse or keyboard when plugged in. kindly refer to some of my contents: How to configure and install Ansible on Azure VM, how to Add or Remove Network Interface from a VM in Azure, how to use Azure key vault secrets in Azure pipelines, and understanding the overview concept of Azure cloud shell.

Razer, a popular computer peripheral manufacturer known for its gaming mice and keyboards. Upon connecting a Razer device to a Windows device, the operating system automatically downloads the Razer Synapse software and initiates its installation on the computer. According to Razer, the Razer Synapse software currently serves over 100 million users worldwide

How is the administrative right obtained? Security researcher Jonhat discovered and tweeted about the zero-day vulnerability in the plug-and-play installation of Razer Synapse that allows users to quickly gain SYSTEM privileges on a Windows device.

SYSTEM privileges are the highest user rights available in Windows and allow someone to execute any command on the operating system. Essentially, when a user is given SYSTEM permissions in Windows, they get complete control of the system and can install anything they want, including malware.

After not receiving a response from Razer, Jonhat disclosed the zero-day vulnerability on Twitter.

It is worth noting that this is a Local Privilege Escalation (LPE) vulnerability. Which means you must have a Razer device and also physical access to the Windows device. Following the attention this zero-day vulnerability gained on Twitter, Razer contacted the security researcher to inform them that they will be issuing a fix.

Jonhat-1

In addition, Razer assured the researcher that they would receive a bug bounty reward, even though the vulnerability had been publicly disclosed.

I hope you found this blog post this vulnerability of administrative rights gained through Razer devices interesting and insightful. Please let me know in the comment session if you have any questions.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Security | Vulnerability Scans and Assessment Tags:Microsoft Windows, Windows 10, Windows 11

Post navigation

Previous Post: How to install and configure an FTP Server on Windows Server
Next Post: How To Use Azure Key Vault Secrets in Azure Pipelines

Related Posts

  • Veeam Zero Trust Data Resilience
    Demystifying Zero Trust with Veeam: Design your Architecture Backup
  • drivelock
    How to perform DriveLock quick setup Security | Vulnerability Scans and Assessment
  • PrintNightMare
    Mitigating ‘PrintNightmare’ Vulnerability: Print Spooler Solutions Security | Vulnerability Scans and Assessment
  • DUE Deligence vs Due Care
    Relating Due Diligence and Due Care to Veeam Backup and Replication Backup
  • Featured image Windows Security
    How to clear Cache and Manually Update Microsoft Defender Anti-Virus Solution
  • Feature image 1
    Configure and validate Exclusions for Microsoft Defender Antivirus scans Anti-Virus Solution

More Related Articles

Veeam Zero Trust Data Resilience Demystifying Zero Trust with Veeam: Design your Architecture Backup
drivelock How to perform DriveLock quick setup Security | Vulnerability Scans and Assessment
PrintNightMare Mitigating ‘PrintNightmare’ Vulnerability: Print Spooler Solutions Security | Vulnerability Scans and Assessment
DUE Deligence vs Due Care Relating Due Diligence and Due Care to Veeam Backup and Replication Backup
Featured image Windows Security How to clear Cache and Manually Update Microsoft Defender Anti-Virus Solution
Feature image 1 Configure and validate Exclusions for Microsoft Defender Antivirus scans Anti-Virus Solution

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • Screenshot 2020 05 16 at 17.41.31
    Tomcat Keystore Update: How to rebind Tomcat Keystore with a new Certificate Web Server
  • How to Remove Language Pack
    How to forcefully remove Language Pack on Windows 10 and 11 Windows
  • update device drivers windows 10 thumbnail
    How to install SCConfigMgr Driver Automation Tool on Windows Windows Server
  • defdfd
    The password has expired: Update your password and try again AWS/Azure/OpenShift
  • Upgrade the embedded PostgreSQL for Veeam Backup and replication
    How to upgrade PostgreSQL Engine used by VBR Backup
  • azure logo 1
    How to use the built-in Azure Active Directory Connect tool AWS/Azure/OpenShift
  • Featured image 1
    How and where to find your BitLocker recovery key on Windows Security | Vulnerability Scans and Assessment
  • AADSTS50020 User from Identity Provider does not exist in Tenant
    AADSTS50020: User from Identity Provider does not exist in Tenant AWS/Azure/OpenShift

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,762 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.