
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2016-20033 is a local privilege escalation vulnerability in Wowza Streaming Engine 4.5.0 caused by improper file permissions that grant the Windows "Everyone" group full access to service executable directories. Authenticated local users can exploit this by replacing the nssm_x64.exe binary in the manager and engine service directories with a malicious executable, which then runs with LocalSystem privileges upon service restart. The vulnerability was originally discovered in 2016 (published by Zero Science Lab as ZSL-2016-5339) but was formally assigned a CVE identifier and published to NVD in March 2026. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (Feedly, Exploit-DB).
The root cause is improper file permission assignment (related to CWE-639 — Authorization Bypass Through User-Controlled Key) on the directories containing the nssm_x64.exe binary used by Wowza Streaming Engine's manager and engine Windows services. Because the "Everyone" group is granted full access to these directories, any authenticated local user can overwrite or replace the service binary without requiring elevated privileges. The attack vector is local, requires low privileges, no user interaction, and has low complexity — making it straightforward to execute once local access is obtained. Public proof-of-concept exploit code has been available since 2016 on Exploit-DB (EDB-40132) and Zero Science Lab (Exploit-DB, Zero Science Lab).
Successful exploitation allows an authenticated local attacker to escalate privileges to LocalSystem — the highest privilege level on a Windows system — resulting in complete compromise of confidentiality, integrity, and availability. With LocalSystem access, an attacker can install malware, exfiltrate sensitive data, disable security controls, create backdoor accounts, and potentially pivot to other systems on the network. The impact is limited to systems running Wowza Streaming Engine 4.5.0 on Windows, but the severity is high given the full system control achieved (Feedly).
Public proof-of-concept exploit code has been available since 2016 via Exploit-DB (EDB-40132) and Zero Science Lab (ZSL-2016-5339), making exploitation technically accessible to low-skilled attackers with local access. The EPSS score is approximately 0.009% (0.000090), indicating a low probability of active exploitation in the near term. There is no current evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, Exploit-DB).
nssm_x64.exe — typically found in the manager and engine service subdirectories (e.g., C:\Program Files\WowzaStreamingEngine\manager\ and C:\Program Files\WowzaStreamingEngine\bin\).icacls or Windows Explorer properties.nssm_x64.exe.nssm_x64.exe with the malicious executable in both the manager and engine service directories.nssm_x64.exe executes with LocalSystem privileges, granting full control of the system (Exploit-DB, Zero Science Lab).nssm_x64.exe in Wowza Streaming Engine manager or engine service directories; file hash mismatch compared to known-good Wowza installation binaries; presence of unknown executables renamed to nssm_x64.exe.cmd.exe, powershell.exe, network tools) running under the SYSTEM account; unexpected outbound network connections from the SYSTEM account.HKLM\SYSTEM\CurrentControlSet\Services\WowzaStreamingEngine) indicating service binary path modification.Organizations should upgrade Wowza Streaming Engine beyond version 4.5.0 to a patched release — contact Wowza Media Systems directly for available updates. As an immediate workaround, restrict file system permissions on the Wowza Streaming Engine installation directories so that only the SYSTEM account and local administrators have write access, removing the "Everyone" group's full-access permissions. Additionally, limit local interactive and remote login access to Wowza servers to only trusted, necessary accounts, and implement file integrity monitoring on nssm_x64.exe and related service binaries to detect unauthorized modifications (Feedly, VulnCheck Advisory).
The vulnerability received limited but notable attention following its formal CVE assignment in March 2026, despite the original discovery dating to 2016. Security aggregators including RedPacket Security, VulDB, and CVEFeed.io published alerts, and the CVE was discussed on Bluesky and Mastodon social platforms. A technical write-up was published on infinitsec.net covering the exploitation mechanics (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."