CVE-2020-5741highunder attackCWE-502

CVE-2020-5741: high-severity vulnerability in Plex Media Server (Windows)

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.2epss 73%
from disclosure to weapon0 days
Published on NVDMay 8
metasploitMay 7
CISA KEV+1036d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2023-03-31

Apply updates per vendor instructions.

In short

Plex Media Server on Windows has a flaw that allows authenticated users to run malicious Python code by sending specially crafted data. This is dangerous because attackers with valid credentials can take full control of the server.

Technical detail

CWE-502 unsafe deserialization vulnerability in Plex Media Server (Windows) enables remote code execution through untrusted serialized data. An authenticated attacker can craft malicious input that executes arbitrary Python code with server privileges, bypassing the authentication requirement for code execution itself.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.