TROYANOSYVIRUS
Back to CVEs

CVE-2016-20033

HIGH
7.8

Description

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart.

CVE Details

CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/16/2026
Last Modified3/19/2026
Sourcenvd
Honeypot Sightings0

Affected Products

wowza:streaming_engine

Weaknesses (CWE)

CWE-639

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.