# CVE-2020-36916

## Summary

- **CVE ID:** CVE-2020-36916
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-732
- **Published:** Jan 6, 2026
- **Last Modified:** Mar 14, 2026

## Description

TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access.

## Affected Products

- Tdmsignage — TDM Digital Signage PC Player (4.1.0.4)

## References

- [CNA](https://www.exploit-db.com/exploits/48953)
- [CNA](https://www.tdmsignage.com)
- [CNA](https://pro.sony/en_NL/products/display-software/tdm-ds1y-tdm-ds3y)
- [CNA](https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5604.php)
- [CNA](https://packetstorm.news/files/id/159723)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/190627)
- [CNA](https://www.vulncheck.com/advisories/tdm-digital-signage-pc-player-privilege-escalation-via-insecure-permissions)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.03%
- **EPSS Percentile:** 8.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._