CVE-2016-20033
HIGHWowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe
Title source: cnaDescription
Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart.
Exploits (1)
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
Vulnerability Advisory
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5339.php
Third Party Advisory third-party-advisory
VulnCheck Advisory: Wowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe
https://www.vulncheck.com/advisories/wowza-streaming-engine-local-privilege-escalation-via-nssm-x64-exe
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
5.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
Status
published
Products (2)
wowza/streaming_engine
4.5.0
Wowza Media Systems, LLC./Wowza Streaming Engine
4.5.0
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026