Synapse
Vendor:
First CVE: Aug 2, 2017 · Active for 8 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Synapse over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2017
8 years ago
Most Recent CVE
Oct 29, 2025
268 days ago
CVE Severity & Scoring
Synapse12 CVEs
25%
67%
8%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (83.3%)
Network1 (8.3%)
Unknown0 (0.0%)
Physical1 (8.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low9 (75.0%)
High0 (0.0%)
None3 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9769CRITICAL A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary proc | Aug 2, 2017 | 9.8 | 89 | NO | YES |
CVE-2021-44226HIGH Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any u | Mar 23, 2022 | 7.3 | 25 | NO | NO |
CVE-2017-14398HIGH rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology involving a handle t | Sep 13, 2017 | 7.8 | 25 | NO | NO |
CVE-2017-11652HIGH Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file. | Aug 18, 2017 | 8.4 | 25 | NO | NO |
CVE-2025-9871HIGH Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations o | Oct 29, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-9870HIGH Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected insta | Oct 29, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-9869HIGH Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of | Oct 29, 2025 | 7.8 | 24 | NO | NO |
CVE-2022-47631HIGH Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLLs into %PROGRAMDATA%\ | Sep 14, 2023 | 7.8 | 23 | NO | NO |
CVE-2017-11653HIGH Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) RazerConfigNative.dll or | Aug 18, 2017 | 7.8 | 23 | NO | NO |
CVE-2021-30494MEDIUM Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operat | Apr 14, 2021 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Synapse
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.5.1030.101917 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.15.1104 | 2 | 8.8 | 42.9% | 0 | 1 |