Hi Parallels Team,
we updated our RAS environment to v17.1.2.1-21873 to prevent CVE-2020-15860.
In your KB article https://kb.parallels.com/en/125112 you write that the Parallels Client must also be on the latest version in order to completely prevent the security problem. Unfortunately, there are several customers who are still using older OS versions that the newer Parallels Client is not compatible with. In addition, not all users have administrator rights for the update or thin clients with write filters are in use.
We understand that it is safest to always use the latest version. For our customers, however, given the number of clients, this involves much more effort than just installing an update.
So my question to you: Is the RAS infrastructure still vulnerable to CVE-2020-15860 without using the latest version of the Parallels Client and how high is the risk if you allow older Parallels Client versions?
I assume that the protocol was adapted to protect the components equally. This is good in my opinion, but takes a lot of flexibility from the software.
Best regards
Patrick
we updated our RAS environment to v17.1.2.1-21873 to prevent CVE-2020-15860.
In your KB article https://kb.parallels.com/en/125112 you write that the Parallels Client must also be on the latest version in order to completely prevent the security problem. Unfortunately, there are several customers who are still using older OS versions that the newer Parallels Client is not compatible with. In addition, not all users have administrator rights for the update or thin clients with write filters are in use.
We understand that it is safest to always use the latest version. For our customers, however, given the number of clients, this involves much more effort than just installing an update.
So my question to you: Is the RAS infrastructure still vulnerable to CVE-2020-15860 without using the latest version of the Parallels Client and how high is the risk if you allow older Parallels Client versions?
I assume that the protocol was adapted to protect the components equally. This is good in my opinion, but takes a lot of flexibility from the software.
Best regards
Patrick