VulnerabilityDeferred
CVE-2020-36916
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files.
HIGH 8.5EPSS 0.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access.
- CVSS 4.0
- 8.5 HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.26% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Source
- disclosure@vulncheck.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/190627
- https://packetstorm.news/files/id/159723
- https://pro.sony/en_NL/products/display-software/tdm-ds1y-tdm-ds3y
- https://www.exploit-db.com/exploits/48953
- https://www.tdmsignage.com
- https://www.vulncheck.com/advisories/tdm-digital-signage-pc-player-privilege-escalation-via-insecure-permissions
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5604.php
- https://www.exploit-db.com/exploits/48953
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.