CVE-2020-5741 Details
Description
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
A deserialization vulnerability allowing remote code execution has been identified in Plex Media Server on Windows. This issue arises from the unsafe unpickling of a 'Dict' file within the application's plugin framework. An authenticated attacker with admin privileges can exploit this vulnerability by uploading a malicious Dict file through the Camera Upload feature, which is then executed by the media server as the user running Plex.
Users are advised to upgrade to Plex Media Server version 1.19.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5741 | CISA-ADP | US Government Resource |
| http://packetstormsecurity.com/files/158470/Plex-Unpickle-Dict-Windows-Remote-Code-Execution.html | CVE | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-32 | CVE | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/158470/Plex-Unpickle-Dict-Windows-Remote-Code-Execution.html | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-32 | [email protected] | ExploitThird Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Plex Media Server Remote Code Execution Vulnerability | Mar 10, 2023 | Mar 31, 2023 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| plex media server | < 1.19.3 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 31, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 19, 2025 | Modified Analysis | [email protected] |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 14, 2021 | Modified Analysis | [email protected] |
| Dec 10, 2021 | CPE Deprecation Remap | [email protected] |
| Jul 17, 2020 | CVE Modified | [email protected] |
| May 14, 2020 | Initial Analysis | [email protected] |