CVE-2023-45894

The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.
Configurations

Configuration 1 (hide)

cpe:2.3:a:parallels:remote_application_server:*:*:*:*:*:*:*:*

History

20 Dec 2023, 16:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 10.0
CWE NVD-CWE-noinfo
Summary
  • (es) El servidor de aplicaciones remotas en Parallels RAS anterior a 19.2.23975 no segmenta las aplicaciones virtualizadas del servidor, lo que permite a un atacante remoto lograr la ejecución remota de código mediante técnicas de ruptura de quiosco estándar.
CPE cpe:2.3:a:parallels:remote_application_server:*:*:*:*:*:*:*:*
References () https://github.com/Oracle-Security/CVEs/blob/main/Parallels%20Remote%20Server/readme.md - () https://github.com/Oracle-Security/CVEs/blob/main/Parallels%20Remote%20Server/readme.md - Third Party Advisory
First Time Parallels
Parallels remote Application Server

14 Dec 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-14 20:15

Updated : 2023-12-20 16:44


NVD link : CVE-2023-45894

Mitre link : CVE-2023-45894

CVE.ORG link : CVE-2023-45894


JSON object : View

Products Affected

parallels

  • remote_application_server