ZeroHour

CVE-2026-36433

niche

Arbitrary Code Execution in Actions Semiconductor Media Player Utilities 4.46

CVSS 3.1
9.8 critical
EPSS
<1%p6
Published
()
Modified
AI analysis

CVE-2026-36433 is an arbitrary code execution flaw (CWE-94, code injection) in the Production.dll and RdiskUpgrade.exe components of Actions Semiconductor Co. Ltd's Tool - Media Player Utilities version 4.46, a utility used to service and upgrade firmware on Actions Semiconductor-based media players. According to the description, a physically proximate attacker can trigger the issue through these components to run arbitrary code, although the advisory is scored 9.8 (critical) with a network attack vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation gives the attacker arbitrary code execution under the privileges of the user running the utility, potentially compromising the workstation and any connected player being flashed or produced. Affected parties are anyone running Tool - Media Player Utilities 4.46, typically device manufacturers, refurbishers, and repair technicians who use the flashing/upgrade tooling. There are no reports of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.

What to do: Inventory Windows workstations where Tool - Media Player Utilities 4.46 is installed, and restrict use of Production.dll and RdiskUpgrade.exe to trusted, dedicated flashing/upgrade machines until a patched release is available from Actions Semiconductor. Because the trigger is described as physically proximate, limiting physical access to machines running the tool and avoiding use of the utility on shared or publicly accessible systems reduces exposure. Monitor the vendor and MITRE for a fixed version, since none is stated in the advisory.

Affected
Actions Semiconductor Co. Ltd Tool - Media Player Utilities4.46 (the only version named in the advisory; no fixed version or other affected ranges are provided)
Estimated exposure
nicheunknown; plausibly on the order of thousands of workstations at device manufacturers, refurbishers, and repair shops — No public install-base, telemetry, or internet-exposure scan data exists for this legacy Windows firmware-upgrade utility; its niche footprint is inferred from its role in production/repair workflows for Actions Semiconductor-based media…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.