VulnerabilityBleeping Computer
8.5 — CRITICAL
Plex warns users to patch security vulnerabilities immediately
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Plex Media Server v1.43.2 and earlier are vulnerable to multiple security flaws, including incorrect resource transfer and deserialization of untrusted data, allowing attackers to steal credentials and execute arbitrary code.
⚙️Technical Details
CVEs
CVE-2025-34158CVE-2020-5741
Affected Systems
Plex Media Server v1.43.2 and earlier on Windows
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Server owners and desktop users running affected versions of Plex Media Server
🛡️Recommended Actions
1Update Plex Media Server to version 1.43.3 and the Plex Desktop client to 1.115.0 as soon as possible
2Secure systems by updating Plex Media Server and desktop clients before attackers reverse-engineer patches
3Monitor for suspicious activity and implement additional security measures
📦Affected Products
Microsoft WindowsPlex Media Server
🔐NVD Verified DataVERIFIED
CVE-2025-34158 ↗CVSS 8.5 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NWeaknesses
CWE-669
CVE-2020-5741 ↗CVSS 7.2 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-502
Affected Products (CPE)
Microsoft WindowsPlex Media Server
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
