{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/rzupdateservice-1.10.14.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-18606"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RzUpdateService (1.10.14.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","windows","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Razer"],"content_html":"\u003cp\u003eRazer RzUpdateService version 1.10.14.0 contains a vulnerability in its Named Pipe Handler component located within C:\\Program Files (x86)\\Razer\\RzUpdateEngineService\\RzUpdateService.exe. This vulnerability arises from improper management of the lpThreadParameter argument. A local attacker can manipulate this parameter to achieve improper privilege management, potentially resulting in privilege escalation. The vulnerability is triggered via the named pipe interface used by the service. Publicly available exploit code exists, increasing the likelihood of local exploitation in environments where this software is installed. Defenders should prioritize updating the software or restricting access to the associated service and named pipes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local user to escalate privileges, potentially gaining SYSTEM-level access on the affected Windows host. This poses a significant risk to workstations or servers where Razer peripherals software is installed, as it allows attackers to bypass standard user restrictions and persist with elevated rights.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit endpoints for the presence of Razer RzUpdateService version 1.10.14.0.\u003c/li\u003e\n\u003cli\u003eApply security patches provided by Razer once available for RzUpdateService.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized processes or scripts attempting to communicate with named pipes associated with Razer update services.\u003c/li\u003e\n\u003cli\u003eReview local group policies to restrict non-administrative users from executing arbitrary code or interacting with service-level pipes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T18:06:00Z","date_published":"2026-08-03T18:06:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-razer-rzupdateservice-privilege-escalation/","summary":"A local privilege escalation vulnerability in Razer RzUpdateService version 1.10.14.0 allows local attackers to manipulate the Named Pipe Handler to gain unauthorized privileges.","title":"Privilege Escalation in Razer RzUpdateService","url":"https://feed.craftedsignal.io/briefs/2026-08-razer-rzupdateservice-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - RzUpdateService (1.10.14.0)","version":"https://jsonfeed.org/version/1.1"}