mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
20 lines
1020 B
Markdown
20 lines
1020 B
Markdown
### [CVE-2023-3513](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3513)
|
||

|
||

|
||

|
||

|
||
|
||
### Description
|
||
|
||
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and triggering an insecure .NET deserialization.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
- https://starlabs.sg/advisories/23/23-3513/
|
||
|
||
#### Github
|
||
- https://github.com/SohelParashar/.Net-Deserialization-Cheat-Sheet
|
||
- https://github.com/star-sg/CVE
|
||
|