https://streamable.com/q2dsji for better quality poc video
-
-
-
Additionally if you go through the installation process and define the save dir to user controllable path like Desktop. A service binary is saved there which can be hijacked for persistance and is executed before user logon on boot.
Show this thread -
I would like to update that I have been reached out by
@Razer and ensured that their security team is working on a fix ASAP. Their manner of communication has been professional and I have even been offered a bounty even though publicly disclosing this issue.Show this thread
End of conversation
New conversation -
-
-
Love this. Have you tried if it's possible to trigger razerinstaller w/o a razor mouse by spoofing the usb vendor/product id?
-
This is a bit out of my comfort zone so idk, I dont see why not unless there are signatures involved. I did try it over RDP (RemoteFX enabled) and was able to trigger the installer, but the session is different from a local one so won't show the window :(
- Show replies
New conversation -
-
-
Wow. Good find. And OTHERWISE I don't use Razr products because the admin app is such a data and resource hog.
Thanks. Twitter will use this info to make your timeline better. UndoUndo
-
-
-
holy fucking shit
Thanks. Twitter will use this info to make your timeline better. UndoUndo
-
-
-
Yeah unfortunately many devices trigger downloaders via Windows Update. I think this happened to me with a Logitech webcam once, and I immediately wondered if this could be done, but I was lazy.
-
The problem isn't the installer itself. It's the installer running as System *and* providing a common file dialog to escape from.
- Show replies
New conversation -
-
-
Thanks. Twitter will use this info to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.