


Perceptive Security
SOC/SIEM Consultancy

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable …
Published:
15 maart 2026 om 23:00:00
Alert date:
16 maart 2026 om 16:21:26
Source:
nvd.nist.gov
Enterprise Applications
CVE-2016-20033 is a local privilege escalation vulnerability in Wowza Streaming Engine 4.5.0. The vulnerability stems from improper file permissions that grant full access to the Everyone group. Authenticated attackers can exploit this by replacing the nssm_x64.exe binary in manager and engine service directories with malicious executables. When services restart, the malicious code executes with LocalSystem privileges. This allows authenticated users to escalate their privileges from normal user to system administrator level. The vulnerability affects the service management components of the streaming engine software.
Technical details
Mitigation steps:
Affected products:
Wowza Streaming Engine
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2016-20033
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5339.php
https://www.exploit-db.com/exploits/40132
https://www.vulncheck.com/advisories/wowza-streaming-engine-local-privilege-escalation-via-nssm-x64-exe
Related CVE's:
Related threat actors:
IOC's:
nssm_x64.exe
This article was created with the assistance of AI technology by Perceptive.
