Installing Razr devices on Windows allows privilege escalation!
#cososec
//
Need local admin and have physical access?
- Plug a Razer mouse (or the dongle)
- Windows Update will download and execute RazerInstaller as SYSTEM
- Abuse elevated Explorer to open Powershell with Shift+Right click
Tried contacting @Razer, but no answers. So here's a freebie https://t.co/xDkl87RCmz
@chirpSec
Funny you should post the o.mg cable, because of course it can imitate a Razr device and automate the driver install process:
@voltronic a 4 dollar raspberry pi pico can do it too.
@voltronic As if I needed more reasons to dislike Razer products. Last headset I got from them was just awful.
@voltronic Computers trust HIDs way too much…