CVE-2019–13142: Razer Surround 1.1.63.0 EoP
ID: e109af75-fc20-590d-90af-e40ec55e5354
STIX ID: report--e109af75-fc20-590d-90af-e40ec55e5354
Feed Name: SpecterOps Blog
Threat Score
**Razer Surround Elevation of Privilege via Insecure ProgramData Permissions** — Razer Surround installed a SYSTEM service (RzSurroundVADStreamingService) whose executable and containing folder under C:\ProgramData had overly permissive ACLs allowing non-privileged users to overwrite the binary; replacing the executable and rebooting allowed execution as SYSTEM. The report details discovery steps, proof-of-concept exploitation, and the coordinated disclosure and fix timeline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
