{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2020-36916","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-01-03T14:10:13.301Z","datePublished":"2026-01-06T15:52:24.815Z","dateUpdated":"2026-01-06T19:38:43.156Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-01-06T15:52:24.815Z"},"datePublic":"2020-09-23T00:00:00.000Z","title":"TDM Digital Signage PC Player 4.1.0.4 Privilege Escalation via Insecure Permissions","descriptions":[{"lang":"en","value":"TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Incorrect Permission Assignment for Critical Resource","cweId":"CWE-732","type":"CWE"}]}],"affected":[{"vendor":"Tdmsignage","product":"TDM Digital Signage PC Player","versions":[{"version":"4.1.0.4","status":"affected"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":8.5,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS"},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"references":[{"url":"https://www.exploit-db.com/exploits/48953","name":"ExploitDB-48953","tags":["exploit"]},{"url":"https://www.tdmsignage.com","name":"TDM Digital Signage Official Website","tags":["product"]},{"url":"https://pro.sony/en_NL/products/display-software/tdm-ds1y-tdm-ds3y","name":"Sony Professional Display Software Product Page","tags":["product"]},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5604.php","name":"Zero Science Lab Disclosure (ZSL-2020-5604)","tags":["third-party-advisory"]},{"url":"https://packetstorm.news/files/id/159723","name":"Packet Storm Security Exploit Entry","tags":["exploit"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/190627","name":"IBM X-Force Vulnerability Exchange","tags":["vdb-entry"]},{"name":"VulnCheck Advisory: TDM Digital Signage PC Player 4.1.0.4 Privilege Escalation via Insecure Permissions","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/tdm-digital-signage-pc-player-privilege-escalation-via-insecure-permissions"}],"credits":[{"lang":"en","value":"LiquidWorm as Gjoko Krstic of Zero Science Lab","type":"finder"}],"x_generator":{"engine":"vulncheck"}},"adp":[{"references":[{"url":"https://www.exploit-db.com/exploits/48953","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-01-06T19:32:38.963380Z","id":"CVE-2020-36916","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-01-06T19:38:43.156Z"}}]}}