Vulnerabilities
Vulnerable Software
Crestron:  >> Airmedia  Security Vulnerabilities
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.
CVSS Score
8.8
EPSS Score
0.002
Published
2022-09-23
Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt.
CVSS Score
8.8
EPSS Score
0.016
Published
2022-09-13
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.
CVSS Score
7.8
EPSS Score
0.003
Published
2022-09-13
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair operation.
CVSS Score
8.8
EPSS Score
0.009
Published
2022-09-13


Contact Us

Shodan ® - All rights reserved