Description
An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
Published: 2026-09-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Remotely
AI Analysis

Impact

The vulnerability exists in the Production.dll and RdiskUpgrade.exe components of Actions Semiconductor Co. Ltd Tool- Media Player Utilities version 4.46. An attacker who can be physically close to the target machine can trigger the flaw and cause arbitrary code to run with the privileges of the component process. The flaw is a form of code execution weakness that would allow an attacker to compromise confidentiality, integrity, or availability of the affected system, potentially leading to full system takeover. The security impact is that compromised components can execute any code, read or modify system files, install additional malware, or create a foothold for further exploitation. The description does not indicate network exposure; the likely attack vector involves physical proximity and the presence of the vulnerable components on the system.

Affected Systems

Actions Semiconductor Co. Ltd Tool- Media Player Utilities version 4.46 is affected. No additional vendor, product, or version data are available from the CNA records. The vulnerability is present in the Production.dll and RdiskUpgrade.exe files included in that release.

Risk and Exploitability

The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog and the EPSS score is not available, so the exploitation probability is unknown. However, the CVSS score and the ability to execute arbitrary code imply a high severity risk. Because the attack requires physical proximity, it may be limited to environments where an attacker can gain physical access, but when this is possible, the impact is severe. No public exploit evidence is provided, but the arbitrary code execution nature makes it a high‑risk vulnerability for systems still running the impacted components.

Generated by OpenCVE AI on September 9, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any vendor‑issued updates or patches for Tool‑ Media Player Utilities v4.46 that address Production.dll and RdiskUpgrade.exe.
  • If no patch is available, disable or remove the Production.dll and RdiskUpgrade.exe components from the system or configure the system to prevent their execution.
  • Limit physical access to affected machines by implementing physical security controls, such as access control badges, monitoring, and locked server rooms to reduce the likelihood of a proximate attacker triggering the flaw.

Generated by OpenCVE AI on September 9, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Physical proximity arbitrary code execution via Actions Semiconductor Media Player Utilities components
Weaknesses CWE-94

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T20:25:46.880Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36433

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T21:17:01.983

Modified: 2026-09-09T21:17:01.983

Link: CVE-2026-36433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T21:30:15Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')