CVE-2020-5740: Input Validation
Published Apr 22, 2020
·Updated
Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges.
Affected Software
2 affected components
Plex media server<1.19.1.2701
Microsoft Windows
Event History
Apr 22, 2020
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-5740.
2
What is the severity of CVE-2020-5740?
The severity of CVE-2020-5740 is high (CVSS score: 7.8).
3
What is the affected software for CVE-2020-5740?
The affected software for CVE-2020-5740 is Plex Media Server on Windows (up to version 1.19.1.2701).
4
What can an attacker do with CVE-2020-5740?
An attacker can execute arbitrary Python code with SYSTEM privileges.
5
Is Microsoft Windows vulnerable to CVE-2020-5740?
No, Microsoft Windows is not vulnerable to CVE-2020-5740.