logo

CVE-2019–13142: Razer Surround 1.1.63.0 EoP

ID: e109af75-fc20-590d-90af-e40ec55e5354

STIX ID: report--e109af75-fc20-590d-90af-e40ec55e5354

Feed Name: SpecterOps Blog

Threat Score
50/100

Date Published: 2019-07-05

Date Updated: 2026-04-30

Author: Matt Nelson

...
...

**Razer Surround Elevation of Privilege via Insecure ProgramData Permissions** — Razer Surround installed a SYSTEM service (RzSurroundVADStreamingService) whose executable and containing folder under C:\ProgramData had overly permissive ACLs allowing non-privileged users to overwrite the binary; replacing the executable and rebooting allowed execution as SYSTEM. The report details discovery steps, proof-of-concept exploitation, and the coordinated disclosure and fix timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.