First published: Thu Dec 14 2023(Updated: )
The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Parallels Remote Application Server | <19.2.23975 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45894 has been assigned a critical severity due to its potential for remote code execution.
Fix CVE-2023-45894 by upgrading to Parallels Remote Application Server version 19.2.23975 or later.
CVE-2023-45894 affects all versions of Parallels Remote Application Server prior to 19.2.23975.
CVE-2023-45894 is a remote code execution vulnerability that allows attackers to exploit insecure application segmentation.
Yes, CVE-2023-45894 can be exploited by a remote attacker without any need for authentication.