Razer is fixing a serious Windows security flaw caused by its mice

Share this post

A rather unusual vulnerability in Razer mice has been identified and the company is currently working on a fix. Over the weekend, security researcher Jon Hat posted on Twitter that after plugging in a Razer mouse or dongle, Windows Update will download the Razer installer executable and run it with SYSTEM privileges. It also lets you access the Windows file explorer and Powershell with “elevated” privileges — which essentially means someone with physical access to the computer could install harmful software.

Since this vulnerability requires direct, physical access to a computer, it’s not nearly as dangerous as a security issue that can be carried out remotely, but it’s still a troubling find. Hat said on Twitter that Razer eventually reached out and told him that the company’s security team was working on a fix. We’ve reached out to Razer as well to verify these details and will update this story if we hear anything, including when users might expect the issue to be fixed. We’re also hoping to find out what specific Razer mice can cause the issue.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.

Source: Engadget


Share this post

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top