---
id: CVE-2025-9870
title: >-
  Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege
  Escalation Vulnerability
summary: >-
  Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege
  Escalation Vulnerability. This vulnerability allows local attackers to
  escalate privileges on affected installations of Razer Synapse 3. An attacker
  must first obtai…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-59
vendor: razer
product: synapse
affected:
  - synapse < 3.10.730.71519
patched:
  - synapse 3.10.730.71519
published: '2025-10-29'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9870'
references:
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-25-921/'
    label: zdi-disclosures@trendmicro.com
tags:
  - nvd
epss: 0.00195
epssPercentile: 0.08388
zeroDay: true
ingestedAt: '2026-10-08T11:31:27.682Z'
---

## Overview

Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the Philips HUE module installer. By creating a symbolic link, an attacker can abuse the installer to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-26375.

## Affected

- `synapse < 3.10.730.71519`

## Remediation

Upgrade past the affected range:

- `synapse 3.10.730.71519`
