EXPOSURES › CVE-2020-5741
CVE-2020-5741
HIGH ⌖ ON CISA KEV · EXPLOITEDPlex Media Server RCE due to malicious uploads
Plex's Media Server allowed attackers to upload malicious files through the Camera Upload feature, enabling remote code execution. This was actively exploited in the wild, posing a significant security risk to DIB organizations using the product.
Shame score — Active exploitation of a remote code execution vulnerability by an unauthorized party.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.