Description
An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
Published: 2026-09-09
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Remotely
AI Analysis

Impact

The vulnerability exists in the Production.dll and RdiskUpgrade.exe components of Actions Semiconductor Co. Ltd Tool‑ Media Player Utilities version 4.46. An attacker who can be physically close to the target machine can trigger the flaw and cause arbitrary code to run with the privileges of the component process. The flaw is a form of code execution weakness that would allow availability of the affected system, potentially leading to full system takeover. The security impact is that compromised components can execute any code, read or modify system files, install additional malware, or create a foothold for further exploitation. The description does not indicate network exposure; the likely attack vector involves physical proximity and the presence of the vulnerable components on the system.

Affected Systems

Actions Semiconductor Co. Ltd Tool‑ Media Player Utilities version 4.46 is affected. No additional vendor, product, or version data are available present in the Production.dll and RdiskUpgrade.exe files included in that release.

Risk and Exploitability

The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog and the EPSS score is <1% (0.00166). The low EPSS score indicates a low likelihood of exploitation, but the CVSS score of 9.8 and the ability to execute arbitrary code imply a high severity risk. Because the attack requires physical proximity, it may be limited to environments where an attacker can gain physical access, but when this is possible, the impact is severe. No public exploit evidence is provided, but the arbitrary code execution nature makes it a high‑risk vulnerability for systems still running the impacted components.

Generated by OpenCVE AI on September 11, 2026 at 00:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any vendor‑issued updates or patches for Tool‑ Media Player Utilities v4.46 that address Production.dll and RdiskUpgrade.exe.
  • If no patch is available, disable or remove the Production.dll and RdiskUpgrade.exe components from the system or configure the system to prevent their execution.
  • Limit physical access to affected machines by implementing physical security controls, such as access control badges, monitoring, and locked server rooms to reduce the likelihood of a proximate attacker triggering the flaw.

Generated by OpenCVE AI on September 11, 2026 at 00:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Production.dll and RdiskUpgrade.exe in Tool‑Media Player Utilities

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Physical proximity arbitrary code execution via Actions Semiconductor Media Player Utilities components

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Physical proximity arbitrary code execution via Actions Semiconductor Media Player Utilities components
Weaknesses CWE-94

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-10T15:16:29.252Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36433

cve-icon Vulnrichment

Updated: 2026-09-10T15:16:25.252Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T21:17:01.983

Modified: 2026-09-10T16:17:11.753

Link: CVE-2026-36433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:30:15Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')