CVE-2016-20033 PUBLISHED

Wowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe

Assigner: VulnCheck
Reserved: 15.03.2026 Published: 15.03.2026 Updated: 16.03.2026

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Wowza Media Systems, LLC.
Product Wowza Streaming Engine
Versions
  • Version 4.5.0 is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE