Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. These flaws have not yet been assigned CVE IDs for easy tracking, and while Plex didn't provide additional details on Tuesday, the security issues are known to affect Plex Media Server v1.43.2 and earlier. Plex also emailed users running affected versions and asked them to update as soon as possible to address these security flaws. "We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible," the company said. "CVEs have been requested and we'll reply to this thread with more details once they're published. If you're running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually." Those running affected versions are advised to secure their systems as soon as possible by updating Plex Media Server to version 1.43.3 (released on May 19) and the Plex Desktop client to 1.115.0 (released on August 13), which can be downloaded from the official downloads page or the server management page. Although Plex hasn't shared any details about these vulnerabilities so far, users should follow the company's advice and secure their systems before attackers reverse-engineer the patches and develop an exploit. While Plex has...
Plex warns users to patch security vulnerabilities immediately
Affected Software
Frequently Asked Questions
Which Plex installations are known to be affected?
The security issues are known to affect Plex Media Server version 1.43.2 and earlier. Plex also urged all Plex Desktop users to update, but the article does not specify which earlier Desktop versions are affected.
What versions should administrators and users install?
Plex recommends updating Plex Media Server to version 1.43.3 and Plex Desktop to version 1.115.0 as soon as possible. The server update was released on May 19, and the Desktop update was released on August 13.
What should NAS users do if their package manager has not received the update?
Plex said the updated Media Server version may not yet be available through NAS package managers. In that case, users can install the package manually.
Are CVE identifiers or technical details available for these vulnerabilities?
No CVE IDs had been assigned at the time of the warning, and Plex did not provide additional technical details. The company said CVEs have been requested and that it will provide more information once they are published.