TDM Digital Signage PC Player 4.1.0.4 Privilege Escalation via Insecure Permissions
Vulnerability Description
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36916
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- LiquidWorm as Gjoko Krstic of Zero Science Lab
References
- https://www.exploit-db.com/exploits/48953
- https://www.tdmsignage.com
- https://pro.sony/en_NL/products/display-software/tdm-ds1y-tdm-ds3y
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5604.php
- https://packetstorm.news/files/id/159723
- https://exchange.xforce.ibmcloud.com/vulnerabilities/190627
- https://www.vulncheck.com/advisories/tdm-digital-signage-pc-player-privilege-escalation-via-insecure-permissions
Affected Vendor
Tdmsignage
View all reports →