CVE-2020-36916
8.8TDM · Digital Signage PC Player
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability due to insecure file permissions, allowing authenticated users to replace executables with malicious binaries.
Executive summary
A critical privilege escalation vulnerability in TDM Digital Signage PC Player 4.1.0.4 allows authenticated users to gain elevated system access by modifying application executables.
Vulnerability
The application improperly assigns Modify permissions to the Authenticated Users group for its installation directory and core executable files. This flaw allows any user with local access to the system to replace legitimate binaries with malicious code, which will subsequently execute with elevated privileges.
Business impact
Successful exploitation of this vulnerability enables a local attacker to achieve full system compromise, effectively bypassing standard operating system security controls. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to unauthorized data access, persistence of malicious payloads, and complete control over the signage hardware.
Remediation
Immediate Action: Since no official patch is currently identified, restrict file system permissions on the TDM installation directory to ensure that only the Administrators group has Modify or Write access, while limiting standard users to Read and Execute permissions.
Proactive Monitoring: Audit system logs for unexpected modifications to executable files within the TDM program folder and monitor for the creation of unauthorized local user accounts or unusual process execution patterns.
Compensating Controls: Implement Endpoint Detection and Response (EDR) solutions to flag or block unauthorized binary execution and restrict local user login capabilities on dedicated signage hardware to minimize the attack surface.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exploit is available via Exploit-DB (EDB-ID 48953) and Packet Storm.
Analyst recommendation
The presence of a publicly available exploit combined with the ease of privilege escalation necessitates immediate action. Administrators must manually harden the file system permissions for the affected directory to prevent local users from performing unauthorized binary substitution until a vendor-supplied update is available.
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- ExploitDB-48953 Exploit / PoC
- TDM Digital Signage Official Website
- Sony Professional Display Software Product Page
- Zero Science Lab Disclosure (ZSL-2020-5604) Third-party advisory
- Packet Storm Security Exploit Entry Exploit / PoC
- IBM X-Force Vulnerability Exchange Vulnerability database entry
- VulnCheck Advisory: TDM Digital Signage PC Player 4.1.0.4 Privilege Escalation via Insecure Permissions Third-party advisory