Local Code Execution Vulnerability in Plex Media Server by Plex
CVE-2021-42835
Key Information:
- Vendor
Plex
- Status
- Vendor
- CVE Published:
- 8 December 2021
Badges
What is CVE-2021-42835?
A vulnerability exists in Plex Media Server versions up to 1.24.4.5081-e362dc1ee, which allows an attacker with limited access to exploit an exposed Remote Procedure Call (RPC) service. This issue, stemming from a Time-of-Check to Time-of-Use (TOCTOU) race condition, enables the attacker to run arbitrary code in the context of the Plex update service, which operates with SYSTEM privileges. This situation poses a significant risk, as it can lead to unauthorized actions on the system where Plex is installed, especially if the attacker has gained a foothold via a low-privileged user account.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
