CISA has added an almost three-year-old high-severity remote code execution (RCE) vulnerability in the Plex Media Server to its catalog of security flaws exploited in attacks.
Tracked as CVE-2020-5741, this security flaw allows threat actors with admin privileges to execute arbitrary Python code remotely in low-complexity attacks that don't require user interaction.
@thesecurityaficionado
#cisa #highseverity #remotecodeexecution #RCE #vulnerability #PlexMediaServer #exploited #attacks #execute #maliciouscode #LastPass #credentials #databreach #exfiltrated #productionbackups #criticaldatabase #backups.