You can gain admin rights of Windows 10 just by plugging in a Razer mouse
The PrintNightmare vulnerability makes the hacker community and security researchers pay attention to vulnerabilities that appear on Microsoft products when installing third-party drivers.
Recently, researcher Jonhat discovered a new vulnerability that allows to gain admin rights of Windows 10 just by plugging a Razer mouse into the computer.
Specifically, when plugging in a Razer mouse or the USB end of a Razer wireless mouse, Windows Update will download and execute the RazerInstaller driver under admin rights. Next, Razer's driver installer and device customization software allows users to open an Explorer window to choose where to store the installation files.
On that Explorer window, just press Shift + Right-click and a Powershell window with admin rights will be displayed. Basically, a skilled hacker can use a Powershell window with admin rights to do whatever he wants.
In addition, if the user performs the installation and specifies the directory to save the installation file in a user-controllable path such as the Desktop, the installer will save a service binary there. This binary can be edited to execute code before the user logs in on startup.
Hackers don't even need a real Razer mouse because the USB ID can be spoofed easily.
Jonhat said he tried to contact Razer but was unsuccessful. So he decided to make it public. It is likely that Microsoft will soon recognize the problem and proceed to remove the Razer driver from Windows Update. However, Razer's involvement is still required to edit their drivers before hackers can exploit this vulnerability.
- How to get admin rights on Windows
- 6 Ways to Run Software with Administrator Rights in Windows
- Losing Admin permissions on Windows 10 / 8.1, this is a fix
- How to launch Admin rights application for User account in Windows?
- Razer announces two new Basilisk gaming mouse models with 'terrorist' battery life
- How to assign Administrator permissions on a Windows 7 computer?
- How to grant Admin rights to a User in Win 10
- How to assign admin rights to users in Ubuntu
- How to fix Admin error restricting Windows login
- Razer's new wireless mouse has a battery life of up to 350 hours
- How to run Task Manager with admin rights in Windows 11
- How to open Notepad with admin rights
- 4 ways to run the software using administrative rights in Windows
- How to Uninstall Razer Synapse on PC or Mac