CVE-2016-20033

HIGH

Wowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20033. PoCs published by LiquidWorm.

AI-analyzed exploit summary The writeup details a local privilege escalation vulnerability in Wowza Streaming Engine 4.5.0 due to improper file permissions (Everyone:F) and unquoted service paths, allowing authenticated users to replace executable files with malicious binaries.

Description

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart.

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textlocalwindows
https://www.exploit-db.com/exploits/40132

The writeup details a local privilege escalation vulnerability in Wowza Streaming Engine 4.5.0 due to improper file permissions (Everyone:F) and unquoted service paths, allowing authenticated users to replace executable files with malicious binaries.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Wowza Streaming Engine 4.5.0 (build 18676)
Auth required
Prerequisites: Authenticated local user access · File system write permissions
devstral-2 · analyzed Mar 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-40132
https://www.exploit-db.com/exploits/40132
Vendor Advisory vendor-advisory
Vulnerability Advisory
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5339.php
Third Party Advisory third-party-advisory
VulnCheck Advisory: Wowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe
https://www.vulncheck.com/advisories/wowza-streaming-engine-local-privilege-escalation-via-nssm-x64-exe

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 10.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-639
Status published
Products (2)
wowza/streaming_engine 4.5.0
Wowza Media Systems, LLC./Wowza Streaming Engine 4.5.0
Published Mar 16, 2026
Tracked Since Mar 16, 2026