The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.
References
Link | Resource |
---|---|
https://github.com/Oracle-Security/CVEs/blob/main/Parallels%20Remote%20Server/readme.md | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-12-14 20:15
Updated : 2023-12-20 16:44
NVD link : CVE-2023-45894
Mitre link : CVE-2023-45894
CVE.ORG link : CVE-2023-45894
JSON object : View
Products Affected
parallels
- remote_application_server
CWE