A vulnerability labeled as critical has been found in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:Program Files (x86)RazerRzUpdateEngineServiceRzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management.

This vulnerability appears as CVE-2026-18606. The attack requires local access. In addition, an exploit is available.

The vendor was contacted early about this disclosure.