PT-2026-61598 · Parsec · Parsec
CVE-2026-25039
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Parsec (affected versions not specified)
Description
Parsec is a cloud-based application for secure file sharing. The application fails to sanitize the workspace name when creating a mountpoint in the Windows filesystem to mount an organization's workspace. Because the workspace name can contain the `` character, it can be set to a UNC (Universal Naming Convention) path. If the UNC path is valid, the system interacts with it, which allows an attacker to retrieve the
NTLM (New Technology LAN Manager) hash, a protocol used for authentication in Windows environments. If the path is invalid or the resource is unavailable, the application becomes unresponsive.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parsec