<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>RzUpdateService (1.10.14.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/rzupdateservice-1.10.14.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 03 Aug 2026 18:06:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/rzupdateservice-1.10.14.0/feed.xml" rel="self" type="application/rss+xml"/><item><title>Privilege Escalation in Razer RzUpdateService</title><link>https://feed.craftedsignal.io/briefs/2026-08-razer-rzupdateservice-privilege-escalation/</link><pubDate>Mon, 03 Aug 2026 18:06:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-razer-rzupdateservice-privilege-escalation/</guid><description>A local privilege escalation vulnerability in Razer RzUpdateService version 1.10.14.0 allows local attackers to manipulate the Named Pipe Handler to gain unauthorized privileges.</description><content:encoded><![CDATA[<p>Razer RzUpdateService version 1.10.14.0 contains a vulnerability in its Named Pipe Handler component located within C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe. This vulnerability arises from improper management of the lpThreadParameter argument. A local attacker can manipulate this parameter to achieve improper privilege management, potentially resulting in privilege escalation. The vulnerability is triggered via the named pipe interface used by the service. Publicly available exploit code exists, increasing the likelihood of local exploitation in environments where this software is installed. Defenders should prioritize updating the software or restricting access to the associated service and named pipes.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local user to escalate privileges, potentially gaining SYSTEM-level access on the affected Windows host. This poses a significant risk to workstations or servers where Razer peripherals software is installed, as it allows attackers to bypass standard user restrictions and persist with elevated rights.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit endpoints for the presence of Razer RzUpdateService version 1.10.14.0.</li>
<li>Apply security patches provided by Razer once available for RzUpdateService.</li>
<li>Monitor for unauthorized processes or scripts attempting to communicate with named pipes associated with Razer update services.</li>
<li>Review local group policies to restrict non-administrative users from executing arbitrary code or interacting with service-level pipes.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>windows</category><category>vulnerability</category></item></channel></rss>