Description
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access.
Problem types
Incorrect Permission Assignment for Critical Resource
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/48953
www.exploit-db.com/exploits/48953 (ExploitDB-48953)
www.tdmsignage.com (TDM Digital Signage Official Website)
pro.sony/en_NL/products/display-software/tdm-ds1y-tdm-ds3y (Sony Professional Display Software Product Page)
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5604.php (Zero Science Lab Disclosure (ZSL-2020-5604))
packetstorm.news/files/id/159723 (Packet Storm Security Exploit Entry)
exchange.xforce.ibmcloud.com/vulnerabilities/190627 (IBM X-Force Vulnerability Exchange)
www.vulncheck.com/...ege-escalation-via-insecure-permissions (VulnCheck Advisory: TDM Digital Signage PC Player 4.1.0.4 Privilege Escalation via Insecure Permissions)