CVE-2023-45894: Critical severity Parallels Remote Application Server vulnerability
Published Dec 14, 2023
·Updated
The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.
Affected Software
1 affected component
Parallels Remote Application Server<19.2.23975
Event History
Dec 14, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-45894?
CVE-2023-45894 has been assigned a critical severity due to its potential for remote code execution.
2
How do I fix CVE-2023-45894?
Fix CVE-2023-45894 by upgrading to Parallels Remote Application Server version 19.2.23975 or later.
3
What software is affected by CVE-2023-45894?
CVE-2023-45894 affects all versions of Parallels Remote Application Server prior to 19.2.23975.
4
What type of vulnerability is CVE-2023-45894?
CVE-2023-45894 is a remote code execution vulnerability that allows attackers to exploit insecure application segmentation.
5
Can CVE-2023-45894 be exploited without authentication?
Yes, CVE-2023-45894 can be exploited by a remote attacker without any need for authentication.