One of our vulnerability scanners identified freePBX is insecure regarding Intel Media SDK.
Intel Media SDK installed
FFmpeg compiled with Intel Media SDK support
No processes using Intel Media SDK
The Intel Media SDK package appears to be an unused capability compiled into FFmpeg rather than an actively used component.
My question is - Are we able to replace FFmpeg with a build that does not include Media SDK support.
You could probably replace the binary if it were located in the same location and accepting the same options and producing the same output – not sure if that is the case tho 
But what is the risk here ? Lots of hits on FFmpeg lately and it is a really great project so more details on the report/link might be helpful.
Vulnerability: "The version of Intel Media SDK installed on the remote host is affected by multiple vulnerabilities.
The version of Intel Media SDK installed on the remote host is affected by multiple vulnerabilities:
- Improper input validation in Intel Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access. (CVE-2023-48368)
- Improper buffer restrictions in Intel Media SDK all versions may allow an authenticated user to potentially enable escalation of privilege via local access. (CVE-2023-45221)
- Out-of-bounds read in Intel Media SDK and some Intel oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access. (CVE-2023-22656)
- Out-of-bounds write in Intel Media SDK all versions and some Intel oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access. (CVE-2023-47282)
- Improper buffer restrictions in Intel Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access. (CVE-2023-47169)
Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number