HIGH

CVE-2021-42835

CVSS v3

7

HIGH

EPSS Score

14.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).

Technical details

Published
12/8/2021

Frequently asked questions

What is CVE-2021-42835?

An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).

Is CVE-2021-42835 actively exploited?

Active exploitation of CVE-2021-42835 has not been confirmed. The EPSS score is 14.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-42835?

CVE-2021-42835 has a CVSS v3 base score of 7 (HIGH severity).

Is CVE-2021-42835 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.