CWE-749Base3 in KEV

Exposed Dangerous Method or Function

Incomplete in the CWE catalog · 172 CVEs mapped

172
CVEs mapped
3
In KEV
7.8
Median CVSS
What it is

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Recent examples
7.8cvss
CVE-2026-18263

CVE-2026-18263 - HIGH Severity Vulnerability

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28886.

HIGHno explanation yet
0%
epss
7.8cvss
CVE-2026-18262

CVE-2026-18262 - HIGH Severity Vulnerability

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28885.

HIGHno explanation yet
0%
epss
7.8cvss
CVE-2026-13121

CVE-2026-13121 - HIGH Severity Vulnerability

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-29220.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-749
Abstraction
Base
Structure
Simple
Status
Incomplete
References (2)