CVE-2020-15860 is a critical business logic error in Parallels Remote Application Server (RAS) version 17.1.1. This vulnerability allows an authenticated user to achieve remote code execution by executing arbitrary applications on the backend operating system, even if those applications are not explicitly published. The flaw also permits access to any host within the internal domain, regardless of published applications or server farm association. With a CVSS score of 9.9 (Critical), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows minimal community discussion or media coverage, indicating a lack of widespread public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.1.1CPE matchmatch criteria | cpe:2.3:a:parallels:remote_application_server:17.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.