Blog Layout

Popular Gaming Company Has An Installation Software Server Vulnerability

sccomputerguys • Sep 07, 2021

You may not be familiar with the name "SteelSeries" unless you're a gamer.

The company makes an exceptional line of gaming gear including keyboards, mice, and gaming headsets.

If you buy one of their devices you will undoubtedly use the company's app to install and configure your new gear.

Unfortunately, the app has a bug that can be exploited by hackers to take full control of your system. You don't even need to actually own a SteelSeries device although it is unlikely that you'd install the app if you didn't have one.

The bug was discovered by a researcher named Lawrence Amer. He began investigating the SteelSeries installation app after hearing about a similar bug that impacted the Razer Synapse software. The theory was that since the two companies made similar products, their installation apps may suffer from similar weaknesses and limitations. That theory proved to be absolutely correct.

A spokesperson for SteelSeries had this to say about this issue:

" We are aware of the issue identified and have proactively disabled the launch of the SteelSeries installer that is triggered when a new SteelSeries device is plugged in. This immediately removes the opportunity for an exploit and we are working on a software update that will address the issue permanently and be released soon."

This is a somewhat exotic attack that won't impact a huge number of consumers so your risk is relatively low. Low risk is still greater than no risk, however. If you're a gamer just be aware that these issues exist and keep an eye out for the coming patch. The company hasn't released an ETA yet so we don't know for sure when it's coming but we know that it is.

Kudos to Mr. Amer for his keen eye and to SteelSeries for their prompt attention to the matter.

By sccomputerguys 22 Jul, 2022
Do you own one or more of the following products made by Cisco? The RV110W Wireless-N VPN Firewall The RV130 VPN Router The RV130W Wireless-N Multifunction VPN Router The RV215W Wireless-N VPN ...
By sccomputerguys 21 Jul, 2022
Do you use Microsoft Teams?  If so, you'll be thrilled to know that the Redmond Giant is continuing to pour resources into improving the software with a specific focus on audio and ...
By sccomputerguys 20 Jul, 2022
Corporate branding can be worth its weight in gold and certain images are absolutely iconic.  The Golden Arches, the Nike "swoosh," and Apple's Apple all come to mind. Logo images give companies ...
By sccomputerguys 19 Jul, 2022
Remember the Heartbleed scare we had a couple years back?  It was a nasty side-channel attack that was somewhat exotic and difficult to pull off, and it was absolutely devastating and sent ...
By sccomputerguys 18 Jul, 2022
Microsoft Exchange servers are once more in the crosshairs of hackers around the world.  Most recently, hacking groups have been specifically targeting them to deploy BlackCat ransomware. As is common among ransomware ...
By sccomputerguys 16 Jul, 2022
If you grew up in the days before the internet, it's absolutely staggering to think of all the ways that mobile technology has changed our lives (and mostly for the better). Remember ...
By sccomputerguys 15 Jul, 2022
It may seem as though Internet Explorer is the browser that will not die, but according to Microsoft, it is now a step closer to breathing its last virtual breath. Microsoft has ...
By sccomputerguys 14 Jul, 2022
If you're involved with IT Security at any level and if your network includes Linux servers, keep a watchful eye out for the new Panchan botnet. It first appeared in the wilds ...
By sccomputerguys 13 Jul, 2022
These days, companies spend significant sums of money to protect themselves from cyber criminals.  The threat matrix is vast, and attacks can come from almost any quarter. That is why many companies ...
By sccomputerguys 12 Jul, 2022
Do you receive healthcare of any kind from Kaiser Permanente?  If so, be aware that they recently published a data breach notification indicating that an unidentified attacker accessed an email account that ...
More Posts
Share by: