CVE-2016-20033
Wowza Streaming Engine vulnerability analysis and mitigation

Overview

CVE-2016-20033 is a local privilege escalation vulnerability in Wowza Streaming Engine 4.5.0 caused by improper file permissions that grant the Windows "Everyone" group full access to service executable directories. Authenticated local users can exploit this by replacing the nssm_x64.exe binary in the manager and engine service directories with a malicious executable, which then runs with LocalSystem privileges upon service restart. The vulnerability was originally discovered in 2016 (published by Zero Science Lab as ZSL-2016-5339) but was formally assigned a CVE identifier and published to NVD in March 2026. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (Feedly, Exploit-DB).

Technical details

The root cause is improper file permission assignment (related to CWE-639 — Authorization Bypass Through User-Controlled Key) on the directories containing the nssm_x64.exe binary used by Wowza Streaming Engine's manager and engine Windows services. Because the "Everyone" group is granted full access to these directories, any authenticated local user can overwrite or replace the service binary without requiring elevated privileges. The attack vector is local, requires low privileges, no user interaction, and has low complexity — making it straightforward to execute once local access is obtained. Public proof-of-concept exploit code has been available since 2016 on Exploit-DB (EDB-40132) and Zero Science Lab (Exploit-DB, Zero Science Lab).

Impact

Successful exploitation allows an authenticated local attacker to escalate privileges to LocalSystem — the highest privilege level on a Windows system — resulting in complete compromise of confidentiality, integrity, and availability. With LocalSystem access, an attacker can install malware, exfiltrate sensitive data, disable security controls, create backdoor accounts, and potentially pivot to other systems on the network. The impact is limited to systems running Wowza Streaming Engine 4.5.0 on Windows, but the severity is high given the full system control achieved (Feedly).

Exploitability

Public proof-of-concept exploit code has been available since 2016 via Exploit-DB (EDB-40132) and Zero Science Lab (ZSL-2016-5339), making exploitation technically accessible to low-skilled attackers with local access. The EPSS score is approximately 0.009% (0.000090), indicating a low probability of active exploitation in the near term. There is no current evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, Exploit-DB).

Exploitation steps

  1. Gain Local Access: Obtain authenticated local access to a Windows system running Wowza Streaming Engine 4.5.0 (e.g., via phishing, credential theft, or an existing low-privileged account).
  2. Identify Vulnerable Directories: Locate the Wowza Streaming Engine installation directories containing nssm_x64.exe — typically found in the manager and engine service subdirectories (e.g., C:\Program Files\WowzaStreamingEngine\manager\ and C:\Program Files\WowzaStreamingEngine\bin\).
  3. Verify Permissions: Confirm that the "Everyone" group has full write/modify access to the target directories using icacls or Windows Explorer properties.
  4. Prepare Malicious Executable: Craft or obtain a malicious executable (e.g., a reverse shell, backdoor, or privilege-escalating payload) and rename it nssm_x64.exe.
  5. Replace the Binary: Overwrite the legitimate nssm_x64.exe with the malicious executable in both the manager and engine service directories.
  6. Trigger Service Restart: Wait for or trigger a restart of the Wowza Streaming Engine services (e.g., via system reboot, service management commands if accessible, or social engineering an administrator).
  7. Achieve LocalSystem Execution: Upon service restart, the malicious nssm_x64.exe executes with LocalSystem privileges, granting full control of the system (Exploit-DB, Zero Science Lab).

Indicators of compromise

  • File System: Unexpected modification timestamp on nssm_x64.exe in Wowza Streaming Engine manager or engine service directories; file hash mismatch compared to known-good Wowza installation binaries; presence of unknown executables renamed to nssm_x64.exe.
  • Logs: Windows Security Event Log entries (Event ID 4663) showing write access to Wowza service directories by non-administrative accounts; Windows System Event Log entries for unexpected Wowza service restarts.
  • Process: Unusual child processes spawned by Wowza service processes (e.g., cmd.exe, powershell.exe, network tools) running under the SYSTEM account; unexpected outbound network connections from the SYSTEM account.
  • Registry: Changes to Wowza service registry keys (e.g., HKLM\SYSTEM\CurrentControlSet\Services\WowzaStreamingEngine) indicating service binary path modification.

Mitigation and workarounds

Organizations should upgrade Wowza Streaming Engine beyond version 4.5.0 to a patched release — contact Wowza Media Systems directly for available updates. As an immediate workaround, restrict file system permissions on the Wowza Streaming Engine installation directories so that only the SYSTEM account and local administrators have write access, removing the "Everyone" group's full-access permissions. Additionally, limit local interactive and remote login access to Wowza servers to only trusted, necessary accounts, and implement file integrity monitoring on nssm_x64.exe and related service binaries to detect unauthorized modifications (Feedly, VulnCheck Advisory).

Community reactions

The vulnerability received limited but notable attention following its formal CVE assignment in March 2026, despite the original discovery dating to 2016. Security aggregators including RedPacket Security, VulDB, and CVEFeed.io published alerts, and the CVE was discussed on Bluesky and Mastodon social platforms. A technical write-up was published on infinitsec.net covering the exploitation mechanics (Feedly).

Additional resources


SourceThis report was generated using AI

Related Wowza Streaming Engine vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2016-20034HIGH8.7
  • Wowza Streaming Engine logoWowza Streaming Engine
  • cpe:2.3:a:wowza:streaming_engine
NoYesMar 16, 2026
CVE-2016-20033HIGH8.5
  • Wowza Streaming Engine logoWowza Streaming Engine
  • cpe:2.3:a:wowza:streaming_engine
NoYesMar 16, 2026
CVE-2016-20035MEDIUM6.9
  • Wowza Streaming Engine logoWowza Streaming Engine
  • cpe:2.3:a:wowza:streaming_engine
NoYesMar 16, 2026
CVE-2024-52056MEDIUM6.9
  • Wowza Streaming Engine logoWowza Streaming Engine
  • cpe:2.3:a:wowza:streaming_engine
NoYesNov 21, 2024
CVE-2016-20036MEDIUM5.1
  • Wowza Streaming Engine logoWowza Streaming Engine
  • cpe:2.3:a:wowza:streaming_engine
NoYesMar 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management