HomeSecurityPlex patches three vulnerabilities in its Media Server

Plex patches three vulnerabilities in its Media Server

Plex has patched and mitigated three vulnerabilities affecting Plex Media Server for Windows that could allow attackers to take complete control of the underlying system.

Plex Media Server is a desktop app and the backend server for the media streaming service – it's designed for streaming movies, TV shows, music, and photo albums.

The three vulnerabilities identified, called CVE-2020-5740, CVE-2020-5741, and CVE-2020-5742, were discovered by TenableChris Lyne and reported to Plex on May 31.

If attackers exploit all of these security flaws together, they could remotely execute code as SYSTEM and take full control of the operating system, gain access to all files, deploy backdoors, or move between other devices on the same network.

The Plex security team released patches for CVE-2020-5740 on April 24 and CVE-2020-5741 on May 7, and mitigated CVE-2020-5742 through server-side changes.

Plex

Phishing attacks leading to system takeover

According to a proof-of-concept attack, threat actors who would like to take control of devices running unpatched Plex Media Servers would have to start with a phishing email designed to redirect targeted Plex administrators to a Plex Media server controlled by the attackers.

If their trick succeeds and they connect to the malicious server, "the attacker can continuously send requests to the victim's media server," abusing the CORS policy flaw behind CVE-2020-5742 to steal the X-Plex-Token.

Even if the attack stops here, the hackers will have gained access to the victims' media and will gain the ability to change the server's settings.

“As of June 15, 2020, Plex has deployed a server-side notification to notify users if they connect to an application not hosted by Plex,” Tenable explains.

In the next step, attackers would need to use the stolen administrator authentication token to remotely run arbitrary Python code with media server privileges, exploiting the CVE-2020-5741 flaw.

This would allow them to install backdoors on compromised systems, as well as "roam" to other devices on the server's local network.

Attackers then need to exploit the CVE-2020-5740 vulnerability to elevate their privileges to SYSTEM on Windows, taking full control of the underlying system. Of course, this also gives them access to all files.

Update your system to the latest version

To ensure that the servers are secure, update to the latest version.

“We have made a change to our update distribution servers. This change will protect Plex Media Server version 1.18.2 or later,” the Plex Security Team said. “Plex Media Server installations older than 1.18.2 will still be exploitable, and we encourage users running older versions to upgrade.”

“In addition, Plex Media Server versions 1.19.1.2701 & 1.19.2.2702 (and later) have additional protections against future vulnerabilities. We recommend that all users update to one of these versions.”

“Plex Media Server will not automatically update by default, but users can enable this in their settings,” Tenable also explains. “Users can always check the general settings page to see if there are new updates.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS