Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-42835

Опубликовано: 08 дек. 2021
Источник: nvd
CVSS3: 7
CVSS2: 6.9
EPSS Средний

Описание

An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:plex:media_server:*:*:*:*:*:*:*:*
Версия до 1.25.0.5282 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.142
Средний

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-367

Связанные уязвимости

github
около 4 лет назад

An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).

EPSS

Процентиль: 94%
0.142
Средний

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-367