300k+ Plex Media Server instances still vulnerable to attack via CVE-2025-34158
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-5741 | Authenticated Deserialization RCE in Plex Media Server on Windows CVE-2020-5741 is a deserialization-of-untrusted-data flaw (CWE-502) in Plex Media Server on Windows: the server deserializes a serialized Python (pickle) object supplied over the network without adequate validation. A remote attacker who has already authenticated with high-privilege credentials to the server can submit a maliciously crafted serialized object, causing the server to execute arbitrary Python code upon deserialization. Successful exploitation yields code execution in the context of the Plex Media Server process on the Windows host, exposing that machine's data and credentials and, as demonstrated in the 2022 LastPass breach, potentially providing a foothold into connected environments. Windows installations running a release without the vendor's 2020 security fix are affected; Linux/NAS deployments are outside the described scope of this flaw. Exploitation is confirmed: it carries a 72.9% EPSS probability (99th percentile), has public PoC exploits (Tenable TRA-2020-32 and a PacketStorm write-up), was added to CISA's KEV catalog on 2023-03-10, and is publicly linked to the LastPass breach, where an unpatched Plex Media Server on an employee's PC was the entry point. Do: Update Plex Media Server on every Windows host to the latest release per vendor instructions (a fix shipped in 2020), prioritizing machines used by staff with privileged or remote access, and verify versions by inventory since unpatched instances remain common. Because exploitation requires authenticated high-privilege Plex credentials, review and rotate those credentials and check affected hosts for indicators of compromise such as unexpected processes or lateral movement, as demonstrated in the LastPass incident. | 7.2 | 73% | KEV PoC ×2 |
| large≈300,000+ exposed/vulnerable Plex Media Server instances, with the Windows subset affected by this flaw | |
| CVE-2025-34158 | Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner). NVD description · AI analysis pending | 8.5 | <1% | — | — |
Full article532 words · extracted from helpnetsecurity.com · click to collapse
Over 300,000 internet-facing Plex Media Server instances are still vulnerable to attack via CVE-2025-34158, a critical vulnerability for which Plex has issued a fix earlier this month, Censys has warned.

About CVE-2025-34158
Plex Media Server (PMS) is software that allows users to turn their Windows/Linux/macOS computer or their network-attached storage devices into a personal media server. It organizes their movies, music, photos, and other media and enables them to stream the content on nearly any device.
CVE-2025-34158 is an improper input validation vulnerability that affects PMS versions 1.41.7.x to 1.42.0.x, and has been fixed in version 1.42.1.
The flaw’s CVSS score is the highest possible, and tells us that it can be exploited remotely over the internet, without user interaction or attackers having to authenticate first.
The vulnerability is apparently easy to exploit, and could result in a total loss of confidentiality, integrity, and availability. This means that attackers may access private data through it, corrupt it, or making it unavailable for use by crashing or disabling the Plex server.
Upgrade your Plex Media Server
A few days after the security update was released, Plex took the unusual (but not unheard of) step of contacting users via email to urge them to upgrade to Plex Media Server version 1.42.1.10060 or later to fix the issue. Unfortunately, it seems that too many users haven’t felt the need to do it.
Last Friday, Censys flagged 428,083 devices – predominantly located in the US and Europe – exposing the Plex Media Server web interface / login portal to the internet.
“As of Monday, August 25, Censys observes at least 314k instances of the Plex web interface that appear to be running versions 1.41.7.x to 1.42.0.x,” the Censys research team told Help Net Security.
Plex Media Server vulnerabilities have been occasionally exploited by attackers.
Notably, the August 2022 LastPass breach was made possible by attackers putting malware on a LastPass employee’s home computer, after compromising it through a Plex Media Server vulnerability (CVE-2020-5741). This incident proved that compromised Plex installations can also be used as attack footholds.
The good news is that technical details about the vulnerability haven’t been made public and there isn’t a public proof-of-concept (PoC) exploit.
Nevertheless, users have been urged to update to a fixed version. They should also consider securing access to their Plex control panel and their accounts as much as possible.
UPDATE (September 4, 2025, 11:00 a.m. ET):
The CVSS base score for CVE-2025-34158 has been lowered by Mitre after input from the researcher who unearthed the flaw. It now stands at 8.5, and the new vector string indicates that the flaw is remotely exploitable without user interaction, but attackers have to authenicate first with a low-privileged account before deploying the exploit.
The flaw is due to Plex Media Server not properly transfering/importing a resource/behavior to/from another sphere, “in a manner that provides unintended control over that resource.”
The researcher stated that more details about the flaw will be provided in late 2025 or later, depending on whether enough users have upgraded to a fixed version.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/27/plex-media-server-cve-2025-34158-attack/