CVE-2020-5741
Plex Media Server (Windows)
Published 8 May 2020 · updated 17 Jun 2026 · Analyzed
7.2 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Mar 2023, with a remediation deadline of 31 Mar 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
References
- packetstormsecurity.com/files/158470/Plex-Unpickle-Dict-Windows-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- www.tenable.com/security/research/tra-2020-32 · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5741 · US Government Resource