Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34100


A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair operation.


Published

2022-09-13T19:15:09.953

Last Modified

2024-11-21T07:08:52.780

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application crestron airmedia 4.3.1.39 Yes

References