CyberRota Analysis
AI-GeneratedPlex Media Server versions prior to 1.43.3.10861 are vulnerable to a high-severity issue that allows an admin user to write arbitrary files, which can be executed during the transcoding process. This flaw arises from the insecure handling of the TranscoderH264Options preference, enabling potential execution of malicious code without proper verification. Organizations using Plex Media Server, particularly those with administrative access, should prioritize patching this vulnerability to mitigate the risk of unauthorized code execution.
Original NVD Description
Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)