CVE-2024-52052: Stream Target Remote Code Execution in Wowza Streaming Engine
Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52052?
CVE-2024-52052 is a critical vulnerability that allows for high-privilege remote code execution.
How do I fix CVE-2024-52052?
To fix CVE-2024-52052, update Wowza Streaming Engine to version 4.9.1 or later.
Who is affected by CVE-2024-52052?
CVE-2024-52052 affects authenticated Streaming Engine Manager administrators using Wowza Streaming Engine versions below 4.9.1.
What does CVE-2024-52052 allow an attacker to do?
CVE-2024-52052 allows an attacker to define a custom application property and poison a stream target, leading to remote code execution.
Is there a workaround for CVE-2024-52052 until a patch is applied?
There are no recommended workarounds for CVE-2024-52052, so it is advisable to update to the latest version immediately.