CVE-2017-14398: Razer Synapse

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology involving a handle to \Device\PhysicalMemory, IOCTL 0x22A064, and ZwMapViewOfSection.

Affected products

  • Razer Synapse: version 2.20.15.1104 only

Published 2017-09-13. Last modified 2026-06-17.