top of page
perceptive_background_267k.jpg

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable …

Published:

15 maart 2026 om 23:00:00

Alert date:

16 maart 2026 om 16:21:26

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications

CVE-2016-20033 is a local privilege escalation vulnerability in Wowza Streaming Engine 4.5.0. The vulnerability stems from improper file permissions that grant full access to the Everyone group. Authenticated attackers can exploit this by replacing the nssm_x64.exe binary in manager and engine service directories with malicious executables. When services restart, the malicious code executes with LocalSystem privileges. This allows authenticated users to escalate their privileges from normal user to system administrator level. The vulnerability affects the service management components of the streaming engine software.

Technical details

Mitigation steps:

Affected products:

Wowza Streaming Engine

Related links:

Related CVE's:

Related threat actors:

IOC's:

nssm_x64.exe

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page