STAR Labs disclosed two high-severity local privilege escalation vulnerabilities in Razer CentralService affecting Razer Central 7.11.0.558 and earlier. The bugs, tracked as CVE-2023-3513 and CVE-2023-3514, allow a low-privileged Windows user to execute code as SYSTEM through insecure service design in RazerCentralService.exe. One flaw stems from unsafe deserialization of ConnectedAccounts.bin, which is decrypted with a hardcoded AES-CBC key and processed with BinaryFormatter; the other involves unsafe handling of commands received over a broadly accessible named pipe.
According to the advisory, attackers can abuse user-writable paths under C:\ProgramData\Razer\Razer Central\Accounts and the service's permissive named pipe access to trigger privileged functionality. STAR Labs said the exposed UpdateManager interface includes commands such as AddModule and UninstallModules, which can be manipulated with malicious XML to create a fake module and launch an attacker-controlled binary as SYSTEM. The researchers reported exploitation can be triggered during login, restart, or directly through the named pipe, and recommended removing BinaryFormatter, tightening named pipe permissions, sanitizing untrusted input, and correcting directory permissions.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
STAR Labs published details of CVE-2023-3514, a local privilege escalation flaw in Razer Central versions 7.11.0.558 and below. The vulnerability involves unsafe handling of commands over a named pipe, enabling attackers to abuse privileged service functionality and run attacker-controlled code as SYSTEM.
STAR Labs published details of CVE-2023-3513, a local privilege escalation flaw in Razer Central versions 7.11.0.558 and below. The issue stems from insecure deserialization of a user-influenced ConnectedAccounts.bin file, allowing low-privileged users to execute code as SYSTEM.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.