CVE-2023-45894: Parallels Remote Application Server

Critical severity, CVSS 10.0. EPSS: 1.2% chance of exploitation in the next 30 days.

The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.

Affected products

  • Parallels Remote Application Server: before 19.2.23975 (fixed in 19.2.23975)

Published 2023-12-14. Last modified 2026-06-17.