CVE-2022-34102: High severity crestron airmedia vulnerability
Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Crestron AirMedia Windows Application vulnerability?
The vulnerability ID is CVE-2022-34102.
What is the severity of CVE-2022-34102?
The severity of CVE-2022-34102 is high with a severity value of 8.8.
How does CVE-2022-34102 affect the Crestron AirMedia Windows Application?
CVE-2022-34102 is an insufficient access control vulnerability that allows a user to pause the uninstallation of an executable to gain a SYSTEM level command prompt in the Crestron AirMedia Windows Application version 4.3.1.39.
Which version of the Crestron AirMedia Windows Application is affected by CVE-2022-34102?
CVE-2022-34102 affects the Crestron AirMedia Windows Application version 4.3.1.39.
How can I fix the CVE-2022-34102 vulnerability in the Crestron AirMedia Windows Application?
To fix the CVE-2022-34102 vulnerability, it is recommended to update the Crestron AirMedia Windows Application to version 5.5.1.84 or a later version, as advised by Crestron security advisories and release notes.