VYPR

Airmedia

by Crestron

CVEs (4)

  • CVE-2022-40298HigSep 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level…

  • CVE-2022-34102HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt.

  • CVE-2022-34100HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions…

  • CVE-2022-34101HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.