Parallels RAS 客户端 RDP 后端服务暴露危险函数导致本地权限提升漏洞。此漏洞允许本地攻击者在受影响的 Parallels RAS 客户端安装上提升权限。攻击者首先需要获得在目标系统上执行低权限代码的能力,才能利用此漏洞。 该特定缺陷存在于 RAS RDP 后端服务中。问题源于一个被暴露的危险函数。攻击者可利用此漏洞提升权限,并以 SYSTEM 用户上下文执行任意代码。ZDI 编号为 ZDI-CAN-28886。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Parallels | RAS Client | 21.0.26296 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Parallels | RAS Client | 21.0.26296 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18262 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escala | |
| CVE-2026-13121 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escala |
No comments yet