CVE-2019-7656 [Suggested Description] --------------------------------------- A privilege escalation vulnerability in Wowza Streaming Engine allows any unprivileged Linux user to escalate privileges to root. --------------------------------------- [Vulnerability Type] Privilege Escalation --------------------------------------- [Vendor of Product] Wowza Media Systems LLC --------------------------------------- [Affected Product Code Base] Wowza Streaming Engine - Version 4.8.0 and earlier, Issue fixed in 4.8.5 --------------------------------------- [Affected Component] Wowza Streaming Engine --------------------------------------- [Attack Type] Local --------------------------------------- [Impact Code Execution] true --------------------------------------- [Impact Denial of Service] false --------------------------------------- [Attack Vector] The installer sets relaxed permissions on core program files by default. By injecting a malicious payload in one of those files, it will run with same privileges as the Wowza server, root. --------------------------------------- [Has the vendor confirmed or acknowledged the vulnerability?] true