Parallels RAS 客户端 RDP 后端服务存在危险函数暴露漏洞,可导致本地权限提升。该漏洞允许本地攻击者在受影响系统的 Parallels RAS 客户端安装环境中提升权限。要利用此漏洞,攻击者首先必须在目标系统上获得执行低权限代码的能力。 该特定漏洞存在于 RAS RDP 后端服务中,其成因是某个危险函数被不当暴露。攻击者可以利用此漏洞提升权限,并在 SYSTEM 系统账户的上下文中执行任意代码。该漏洞编号为 ZDI-CAN-28885。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Parallels | RAS Client | 21.0.26296 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Parallels | RAS Client | 21.0.26296 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18263 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escala | |
| CVE-2026-13121 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escala |
No comments yet