CVE-2020-5741: high-severity vulnerability in Plex Media Server (Windows)
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
Plex Media Server on Windows has a flaw that allows authenticated users to run malicious Python code by sending specially crafted data. This is dangerous because attackers with valid credentials can take full control of the server.
CWE-502 unsafe deserialization vulnerability in Plex Media Server (Windows) enables remote code execution through untrusted serialized data. An authenticated attacker can craft malicious input that executes arbitrary Python code with server privileges, bypassing the authentication requirement for code execution itself.
The full analysis of this CVE is available in Portuguese →