Razer's vulnerability footprint centers on a focused portfolio of gaming peripherals, peripheral-management software, and lighting-control platforms such as Synapse, Razer Central, and Chroma SDK, products that integrate deeply into consumer and professional gaming ecosystems. The vendor's exposure recurs through privilege-escalation and file-access-control weakness classes—including improper link resolution, incorrect permission assignment, and privilege-management flaws—that reflect the system-level access these management tools require. Vulnerabilities affecting the vendor frequently acquire public exploit code, making timely patching important for users of affected devices and systems. Defenders should monitor this vendor's releases for its peripheral software stack, particularly instances exposed to local or network-accessible escalation paths; live severity and in-the-wild exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Razer over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9769CRITICAL A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary proc | Aug 2, 2017 | 9.8 | 89 | NO | YES |
CVE-2022-29013CRITICAL A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request. | Jun 9, 2022 | 9.8 | 82 | NO | YES |
CVE-2022-29014HIGH A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files. | Jun 9, 2022 | 7.5 | 41 | NO | YES |
CVE-2020-16602HIGH Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Ra | Sep 2, 2020 | 8.1 | 36 | NO | YES |
CVE-2022-45697HIGH Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory. | Feb 27, 2023 | 7.8 | 27 | NO | NO |
CVE-2021-44226HIGH Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any u | Mar 23, 2022 | 7.3 | 25 | NO | NO |
CVE-2017-14398HIGH rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology involving a handle t | Sep 13, 2017 | 7.8 | 25 | NO | NO |
CVE-2017-11652HIGH Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file. | Aug 18, 2017 | 8.4 | 25 | NO | NO |
CVE-2025-9871HIGH Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations o | Oct 29, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-9870HIGH Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected insta | Oct 29, 2025 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Razer.
Media articles that mention a CVE ID that affects a product developed by Razer — matched by CVE ID, not by vendor name.