CVE-2026-36433
Actions Semiconductor Co. Ltd · Media Player Utilities
Actions Semiconductor Media Player Utilities v.4.46 contains a vulnerability in Production.dll and RdiskUpgrade.exe that allows for arbitrary code execution by a physically proximate attacker.
Executive summary
A critical vulnerability in Actions Semiconductor Media Player Utilities allows for arbitrary code execution, posing a severe risk of full system compromise.
Vulnerability
This vulnerability involves an arbitrary code execution flaw residing within the Production.dll and RdiskUpgrade.exe components of the software. The attack vector is identified as network-based, allowing an unauthenticated attacker to exploit the system without requiring user interaction.
Business impact
The ability to execute arbitrary code grants an attacker complete control over the affected system, leading to total loss of confidentiality, integrity, and availability. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it facilitates unauthorized access to sensitive corporate data and potential lateral movement within the network.
Remediation
Immediate Action: Since no specific patch is currently available, users should restrict physical and network access to systems running Media Player Utilities v.4.46.
Proactive Monitoring: Security teams should monitor endpoint logs for suspicious activity involving the execution of Production.dll or RdiskUpgrade.exe.
Compensating Controls: Implement strict network segmentation to isolate affected systems and utilize endpoint detection and response (EDR) solutions to block unauthorized binary execution.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a severe risk to organizational security due to the potential for full system compromise. Administrators are urged to prioritize the removal or isolation of the affected software components until a vendor-supplied update is released to address the underlying flaw.
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written