CVE-2025-9870

7.8

Razer · Synapse 3

A local privilege escalation vulnerability in the Razer Synapse 3 Philips HUE module installer allows attackers to delete arbitrary files and achieve SYSTEM-level code execution.

Executive summary

A local privilege escalation vulnerability in Razer Synapse 3 allows an attacker to gain SYSTEM-level execution, creating a critical risk for Windows host security.

Vulnerability

The flaw exists within the Philips HUE module installer, which fails to properly resolve symbolic links before accessing files. A local attacker with low-privileged access can exploit this link following behavior to delete arbitrary files and escalate privileges to SYSTEM.

Business impact

Successful exploitation grants an attacker full control over the affected Windows system, as the malicious code executes with SYSTEM privileges. This level of access facilitates complete system compromise, including the installation of persistent backdoors, theft of sensitive data, and further lateral movement within the network. Given the CVSS score of 7.8, this vulnerability represents a high-severity risk to organizational assets.

Remediation

Immediate Action: Since a specific patch version is not currently listed, administrators should monitor the official Razer security portal or the Zero Day Initiative advisory (ZDI-25-921) for the release of a corrective update.

Proactive Monitoring: Security teams should monitor system logs for suspicious file system operations or unexpected installer activity originating from the Razer Synapse installation directory.

Compensating Controls: Restrict local user permissions where possible to prevent the execution of arbitrary code, thereby limiting the attacker's ability to trigger the vulnerable installer process.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

This vulnerability presents a significant risk due to the potential for full system compromise. Organizations utilizing Razer Synapse 3 should prioritize testing and applying any forthcoming patches immediately upon release. In the interim, ensure that endpoints are configured with the principle of least privilege to minimize the likelihood of initial code execution.

More Razer CVEs

Sources