CVE-2016-20033
Last modified
CVE-2016-20033 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wowza | Streaming Engine | 4.5.0 |
References
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5339.phpExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/40132Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2016-20033?
How severe is CVE-2016-20033?
How do I fix CVE-2016-20033?
Are you affected by CVE-2016-20033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
