PT-2022-22005 · Crestron · Crestron Airmedia Windows Application
Published
2022-09-13
·
Updated
2022-09-18
·
CVE-2022-34101
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Crestron AirMedia Windows Application version 4.3.1.39
Description
A vulnerability was discovered in the Crestron AirMedia Windows Application, where a user can place a malicious DLL in a certain path to execute code and perform a privilege escalation attack.
Recommendations
For version 4.3.1.39, consider restricting access to the path where the malicious DLL can be placed until a patch is available. As a temporary workaround, monitor the system for any suspicious DLL placements and executions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crestron Airmedia Windows Application