Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-42835

An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.151
EPSS Ranking 94.2%
CVSS Severity
CVSS v3 Score 7.0
CVSS v2 Score 6.9
Products affected by CVE-2021-42835
  • Plex » Media Server » Version: N/A
    cpe:2.3:a:plex:media_server:-
  • Plex » Media Server » Version: 0.9.9.2
    cpe:2.3:a:plex:media_server:0.9.9.2
  • Plex » Media Server » Version: 1.13.2.5154
    cpe:2.3:a:plex:media_server:1.13.2.5154
  • Plex » Media Server » Version: 1.18.2.2029
    cpe:2.3:a:plex:media_server:1.18.2.2029
  • Plex » Media Server » Version: 1.18.2.2029-36236cc4c
    cpe:2.3:a:plex:media_server:1.18.2.2029-36236cc4c
  • Plex » Media Server » Version: 1.19.1.2701
    cpe:2.3:a:plex:media_server:1.19.1.2701
  • Plex » Media Server » Version: 1.19.3
    cpe:2.3:a:plex:media_server:1.19.3
  • Plex » Media Server » Version: 1.21
    cpe:2.3:a:plex:media_server:1.21
  • Plex » Media Server » Version: 1.24.4.5081
    cpe:2.3:a:plex:media_server:1.24.4.5081
  • Microsoft » Windows » Version: N/A
    cpe:2.3:o:microsoft:windows:-


Contact Us

Shodan ® - All rights reserved