Impact
The vulnerability exists in the Production.dll and RdiskUpgrade.exe components of Actions Semiconductor Co. Ltd Tool- Media Player Utilities version 4.46. An attacker who can be physically close to the target machine can trigger the flaw and cause arbitrary code to run with the privileges of the component process. The flaw is a form of code execution weakness that would allow an attacker to compromise confidentiality, integrity, or availability of the affected system, potentially leading to full system takeover. The security impact is that compromised components can execute any code, read or modify system files, install additional malware, or create a foothold for further exploitation. The description does not indicate network exposure; the likely attack vector involves physical proximity and the presence of the vulnerable components on the system.
Affected Systems
Actions Semiconductor Co. Ltd Tool- Media Player Utilities version 4.46 is affected. No additional vendor, product, or version data are available from the CNA records. The vulnerability is present in the Production.dll and RdiskUpgrade.exe files included in that release.
Risk and Exploitability
The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog and the EPSS score is not available, so the exploitation probability is unknown. However, the CVSS score and the ability to execute arbitrary code imply a high severity risk. Because the attack requires physical proximity, it may be limited to environments where an attacker can gain physical access, but when this is possible, the impact is severe. No public exploit evidence is provided, but the arbitrary code execution nature makes it a high‑risk vulnerability for systems still running the impacted components.
OpenCVE Enrichment