Executive brief
Parallels RAS Client is a remote access software component that enables secure desktop connections. A flaw in its RDP Backend Service allows local attackers to escalate privileges to SYSTEM level, potentially gaining full control of affected systems. Exploitation requires an attacker to first obtain low-privilege code execution on the target machine, but once achieved, the vulnerability enables complete system compromise and arbitrary code execution.
Technical details
This vulnerability is a local privilege escalation flaw in the Parallels RAS Client RDP Backend Service, caused by an exposed dangerous function. The vulnerability requires an attacker to have local access and the ability to execute code in a low-privilege context (PR:L). Once triggered, the flaw allows arbitrary code execution in the SYSTEM security context (C:H/I:H/A:H), providing complete system compromise. No user interaction is required (UI:N), and the scope is unchanged (S:U). The vulnerability was fixed in version 21.2 of Parallels RAS Client.
Affected products
- Parallels RAS Client before 21.2
Timeline
- 2026-02-25: disclosed: Vulnerability reported to vendor
- 2026-08-11: patched: Fixed in version 21.2; coordinated public release of advisory