Plug in this Mouse, Get Windows Admin Privileges!

Date:

Share post:

Security researcher Jonhat shared a tweet exposing a zero-day vulnerability in Razer Synapse installation software. A simple plug-and-play USB or dongle can give you Windows admin privileges.

In the computer peripherals industry, Razer is known for its gaming mice and keyboards. The installation software called Synapse automatically gets downloaded when a new device is plugged in for the first time. It abuses the elevated explorer to open Powershell and get admin access.

To put it simply, if one can get admin access to Windows, they can get complete control of the operating system and install any software/hardware and play truant by also installing malware causing huge damage.

The security researcher reached out to Razer to share the vulnerability, however, he did not receive any response from them. He further disclosed the information about the zero-day vulnerability on Twitter, explaining how the bug works.

Once the exploitation began to be widely discussed and tweeted, Razer took cognizance and reached out to Jonhat. In an update, the researcher shared that he was contacted and assured by Razer that the company was working on a fix with high importance. He was also offered a bounty even though the bug was publicly disclosed.

What is PowerShell?

PowerShell is a task automation and configuration management framework from Microsoft, consisting of a command-line shell and the associated scripting language. Since the command opens with admin privileges by default, all the processes get admin access.

The Windows Vulnerability

A spate of critical vulnerabilities has been reported around Windows, the most recent being the Print Spooler bug (CVE-2021-36958). Microsoft had released security patches addressing 44 CVEs in the month of August alone.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...

Model-Borne Consequence: Why OT Security and Data Security Just Became the Same Job

For thirty years we told you industrial cybersecurity was fundamentally different from IT cybersecurity. We were right. Then...

Truth, Transparency, and a Subpoena: Inside TikTok’s Security Crisis with Roland Cloutier

How the former ByteDance CISO led a 3-billion-user platform through congressional hearings, an international ban threat, and the...