CVE-2019-13142: Razer Surround
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.
Affected products
- Razer Surround: version 1.1.63.0 only
Published 2019-07-09. Last modified 2026-06-17.