CVE-2020-16602
Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have access to port 54236 for a registration step.
Razer Chroma SDK Rest Server versiones hasta 3.12.17, permite a atacantes remotos ejecutar programas arbitrarios porque se presenta una condiciĆ³n de carrera en la que un archivo creado bajo "%PROGRAMDATA%\RazerChroma\SDK\Apps" puede ser reemplazado antes de que sea ejecutado por el servidor . El atacante debe tener acceso al puerto 54236 para un paso de registro
Razer Chroma SDK Server version 3.16.02 suffers from a race condition vulnerability that allows for remote file execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-04 CVE Reserved
- 2020-09-02 CVE Published
- 2020-11-26 First Exploit
- 2024-02-23 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://www.angelystor.com/2020/09/cve-2020-16602-remote-file-execution-on.html | Third Party Advisory | |
https://www.youtube.com/watch?v=fkESBVhIdIA | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/49106 | 2020-11-26 | |
http://packetstormsecurity.com/files/160225/Razer-Chroma-SDK-Server-3.16.02-Race-Condition.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://assets.razerzone.com/dev_portal/REST/html/index.html | 2022-12-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Razer Search vendor "Razer" | Chroma Sdk Search vendor "Razer" for product "Chroma Sdk" | <= 3.12.17 Search vendor "Razer" for product "Chroma Sdk" and version " <= 3.12.17" | - |
Affected
|