top of page
perceptive_background_267k.jpg

A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)…

Published:

2 August 2026 at 22:00:00

Alert date:

3 August 2026 at 18:04:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Identity & Access, Zero-Day Vulnerabilities

A vulnerability has been identified in Razer RzUpdateService version 1.10.14.0, specifically in the Named Pipe Handler component of RzUpdateService.exe. The flaw involves improper privilege management triggered by manipulation of the lpThreadParameter argument. The vulnerability requires local access to exploit, limiting remote attack surface, but a public exploit is already available. The issue was responsibly disclosed to the vendor prior to public release. If exploited, an attacker with local access could escalate privileges on the affected system. The vulnerability is tracked as CVE-2026-18606 and is considered high severity due to the availability of a working public exploit.

Technical details

Mitigation steps:

Affected products:

Razer RzUpdateService 1.10.14.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page