Wowza Streaming Engine 4.5.0 Local Privilege Escalation
Posted by deepcore on July 21, 2016 – 4:44 am
Wowza Streaming Engine suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the ‘F’ flag (Full) for ‘Everyone’ group. In combination with insecure file permissions the application suffers from an unquoted search path issue impacting the services ‘WowzaStreamingEngine450’ and ‘WowzaStreamingEngineManager450’ for Windows deployed as part of Wowza Streaming software. Version 4.5.0 build 18676 is affected.
Post a reply
You must be logged in to post a comment.