AUTO-UPDATED

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex has released critical security updates for Plex Media Server and Plex Desktop, urging all users to install the latest versions immediately to patch multiple undisclosed software vulnerabilities.

Key Points

  • Users should update to Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0 to secure their installations.
  • Plex has requested CVE identifiers for the newly discovered flaws but has not yet disclosed specific technical details regarding the vulnerabilities.
  • Owners running Plex on NAS devices may need to perform manual installations if the update is not yet available in their specific package manager.
  • Censys data indicates over 360,000 Plex Media Server web interfaces are currently exposed to the public internet.
  • Previous Plex vulnerabilities have been linked to significant security incidents, including the 2022 LastPass data breach.

Why it Matters

Promptly patching these vulnerabilities is essential to prevent unauthorized access to personal media infrastructure and sensitive account information. Given the history of attackers exploiting Plex flaws to facilitate broader cyberattacks, maintaining updated software is a critical defense for all server administrators.
Internet Published by info@thehackernews.com (The Hacker News)
Read original