vendor:
Wowza Streaming Engine
by:
Gjoko 'LiquidWorm' Krstic
7,2
CVSS
HIGH
Elevation of Privileges
264
CWE
Product Name: Wowza Streaming Engine
Affected Version From: Wowza Streaming Engine 4.5.0 (build 18676)
Affected Version To: Wowza Streaming Engine Manager 4.5.0 (build 18676)
Patch Exists: NO
Related CWE: N/A
CPE: a:wowza_media_systems:wowza_streaming_engine:4.5.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Ultimate SP1 (EN)
2016
Wowza Streaming Engine 4.5.0 Local Privilege Escalation
Wowza Streaming Engine suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full) for 'Everyone' group. In combination with insecure file permissions the application suffers from an unquoted search path issue impacting the services 'WowzaStreamingEngine450' and 'WowzaStreamingEngineManager450' for Windows deployed as part of Wowza Streaming software.
Mitigation:
Ensure that the permissions for the Wowza Streaming Engine and Manager services are properly configured and that the unquoted search path issue is addressed.