Scille Parsec
- < 3.3.3-rc.0
A vulnerability exists in Parsec Cloud versions prior to 3.3.3-rc.0 due to improper sanitization of workspace names. This flaw allows workspace names to include backslashes, potentially creating a Universal Naming Convention (UNC) path. When such a path is mounted in the Windows filesystem, the application may become unresponsive if the path is invalid. However, if the path is valid, the system will interact with the resource, enabling an attacker to capture NTLM authentication hashes.
Exploitation of this vulnerability allows for interception of NTLM hashes from the authenticated user.
To reproduce this vulnerability, create a new workspace in Parsec Cloud with a UNC path as the name, such as '\\192.168.1.3\test'. After sharing the workspace with targeted organization members, their Parsec application will automatically mount the workspace. If the UNC path is invalid, the application will freeze. If valid, it will interact with the UNC resource, allowing NTLM hash retrieval.
Users can update to Parsec Cloud version 3.3.3-rc.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.