CVE-2021-42835
Summary
| CVE | CVE-2021-42835 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-08 15:15:00 UTC |
| Updated | 2021-12-13 17:14:00 UTC |
| Description | An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Media Server Downloads | Plex Media Server for Windows, Mac, Linux, FreeBSD and More |
MISC |
www.plex.tv |
|
| Local Privilege Plexcalation - IRON |
MISC |
ir-on.io |
|
| Security: Regarding CVE-2021-42835 - Announcements - Plex Forum |
MISC |
forums.plex.tv |
|
| experts_teams - BugSec |
MISC |
bugsec.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 691043 Free Berkeley Software Distribution (FreeBSD) Security Update for plex media server (98f78c7a-a08e-11ed-946e-002b67dfc673)