Description
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.
Published: 2026-08-03
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the named pipe handler of Razer RzUpdateService allows a local user to manipulate the lpThreadParameter argument and gain higher privileges than intended. The weakness is a compromise of privilege management, leading to potential elevation of local privileges. The formal classification of the flaw aligns with CWE-266 and CWE-269, both related to improper handling of privileges and unauthorized privilege escalation. The impact is local to the host machine, but any escalation can jeopardize the entire system’s security posture if the attacker obtains administrative rights.

Affected Systems

The vulnerability affects Razer RzUpdateService version 1.10.14.0. It is present on systems that have the RzUpdateEngineService installed, typically within the C:\Program Files (x86)\Razer\RzUpdateEngineService directory. No additional vendor or product ranges are listed beyond this service.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.5, indicating a high severity level. The EPSS score is not available, and the weakness is not listed in the CISA KEV catalog. The attack requires local access; the exploit has been publicly released and could be used if an attacker gains local foothold. The potential for privilege escalation makes it a significant risk for enterprise environments where non‑privileged users could abuse the service. The attack vector is inferred to be local due to the nature of named pipe manipulation and the requirement to invoke the RzUpdateService executable from within the local system.

Generated by OpenCVE AI on August 4, 2026 at 10:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor‑issued patch for RzUpdateService when released by Razer
  • If a patch is unavailable, disable or remove the RzUpdateEngineService so that the named pipe handler cannot be accessed locally
  • Configure local security policy to restrict which user accounts are allowed to start RzUpdateService and monitor activity logs for suspicious pipe usage

Generated by OpenCVE AI on August 4, 2026 at 10:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.
Title Razer RzUpdateService Named Pipe RzUpdateService.exe privileges management
First Time appeared Razer
Razer rzupdateservice
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:razer:rzupdateservice:*:*:*:*:*:*:*:*
Vendors & Products Razer
Razer rzupdateservice
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Razer Rzupdateservice
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T16:56:43.523Z

Reserved: 2026-08-03T07:11:26.825Z

Link: CVE-2026-18606

cve-icon Vulnrichment

Updated: 2026-08-03T16:56:33.383Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T17:16:35.727

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:22:01Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management