Skip to content
Threat Feed
high advisory

Privilege Escalation in Razer RzUpdateService

A local privilege escalation vulnerability in Razer RzUpdateService version 1.10.14.0 allows local attackers to manipulate the Named Pipe Handler to gain unauthorized privileges.

Razer RzUpdateService version 1.10.14.0 contains a vulnerability in its Named Pipe Handler component located within C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe. This vulnerability arises from improper management of the lpThreadParameter argument. A local attacker can manipulate this parameter to achieve improper privilege management, potentially resulting in privilege escalation. The vulnerability is triggered via the named pipe interface used by the service. Publicly available exploit code exists, increasing the likelihood of local exploitation in environments where this software is installed. Defenders should prioritize updating the software or restricting access to the associated service and named pipes.

Impact

Successful exploitation allows a local user to escalate privileges, potentially gaining SYSTEM-level access on the affected Windows host. This poses a significant risk to workstations or servers where Razer peripherals software is installed, as it allows attackers to bypass standard user restrictions and persist with elevated rights.

Recommendation

  • Audit endpoints for the presence of Razer RzUpdateService version 1.10.14.0.
  • Apply security patches provided by Razer once available for RzUpdateService.
  • Monitor for unauthorized processes or scripts attempting to communicate with named pipes associated with Razer update services.
  • Review local group policies to restrict non-administrative users from executing arbitrary code or interacting with service-level pipes.

Immediate actions

Patch Razer RzUpdateService to the latest version to remediate CVE-2026-18606

IT Operations 72h

Threat Hunt

Identify endpoints running Razer RzUpdateService version 1.10.14.0

T1068 high high confidence hunt now

Data: Endpoint inventory