The streaming suite Plex recently dispatched a mass email urging users to upgrade both their client and server installations without delay. Ordinarily, whenever a security flaw surfaces, Plex simply issues a public advisory. This time, however, the company broadcast an email before any CVE identifier had even been assigned. That urgency suggests the vulnerability at hand is exceptionally grave.
Both the Desktop and Server Editions Require Updating
Users running the desktop client should immediately upgrade to Plex Desktop 1.115.0 or later. Likewise, those operating the media server must promptly move to Plex Media Server 1.43.3 or newer. In each case, the changelog notes the remediation of multiple security issues.
For now, Plex has disclosed neither the vulnerability details, nor the severity rating, nor the method of exploitation. Moreover, no evidence indicates that these flaws have been exploited in the wild. Nevertheless, Plex has already requested CVE identifiers. The company intends to publish further technical particulars once those identifiers are approved.
Docker and NAS Users May Need to Update Manually
Updating the client and server editions is relatively straightforward. Linux users, too, can upgrade by downloading the appropriate package. Those who deploy via Docker images, however, must refresh their container image, since containers seldom update themselves automatically.
NAS users, in particular, warrant special caution. The Plex for NAS builds for Synology, QNAP, and TerraMaster all depend on app-store approval, and the newer version may not yet have cleared review. Therefore, rather than waiting for the store to approve it, users are advised to download the installer directly from the official site and upgrade by hand.
Owners who expose their media server to the internet through the default port 32400 should be especially vigilant. Once the flaw becomes public, scanning scripts will inevitably converge upon it. Consequently, upgrading is imperative; otherwise, the entire server could readily fall into hostile hands.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!