Parallels RAS 客户端的 RDP 后端服务暴露了危险函数,导致本地提权漏洞。该漏洞允许本地攻击者在受影响的 Parallels RAS 客户端系统中提升权限。攻击者首先需要在目标系统上获得执行低权限代码的能力,才能利用此漏洞。 具体而言,该缺陷存在于 RAS RDP 后端服务中。问题的根源在于一个被暴露的危险函数。攻击者可利用此漏洞,在 SYSTEM 权限上下文中提升权限并执行任意代码。该漏洞对应编号为 ZDI-CAN-29220。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Parallels | RAS Client | 21.0.26296 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Parallels | RAS Client | 21.0.26296 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18263 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escala | |
| CVE-2026-18262 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escala |
No comments yet