CVE-2021-42835
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).
Se ha detectado un problema en Plex Media Server versiones hasta 1.24.4.5081-e362dc1ee. Un atacante (con un punto de apoyo en un extremo por medio de una cuenta de usuario con pocos privilegios) puede acceder al servicio RPC expuesto del componente de servicio de actualización. Esta funcionalidad RPC permite al atacante interactuar con la funcionalidad RPC y ejecutar código desde una ruta de su elección (local, o remota por SMB) debido a una condición de carrera TOCTOU. Esta ejecución de código es producida en el contexto del servicio de actualización de Plex (que es ejecutado como SYSTEM)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-22 CVE Reserved
- 2021-12-08 CVE Published
- 2024-03-01 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://bugsec.com/experts_teams | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://ir-on.io/2021/12/02/local-privilege-plexcalation | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://forums.plex.tv/t/security-regarding-cve-2021-42835/761510 | 2021-12-13 | |
https://www.plex.tv/media-server-downloads | 2021-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Plex Search vendor "Plex" | Media Server Search vendor "Plex" for product "Media Server" | < 1.25.0.5282 Search vendor "Plex" for product "Media Server" and version " < 1.25.0.5282" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|