First published: Tue Sep 13 2022(Updated: )
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=4.3.1.39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34101 is a vulnerability discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, that allows a user to place a malicious DLL in a certain path to execute code and perform a privilege escalation attack.
The severity of CVE-2022-34101 is rated as high with a severity score of 7.8.
To fix CVE-2022-34101, it is recommended to update the Crestron AirMedia Windows Application to version 5.5.1.84 or later.
You can find more information about CVE-2022-34101 in the Crestron Security Advisories and the AirMedia Windows Installer Release Notes.
CWE-427 is a category of software weaknesses known as Uncontrolled Search Path Element that can lead to the execution of malicious code.