Junglewise Threat Intelligence

CVE-2026-18262: Parallels RAS Client privilege escalation in RDP Backend Service

CVE-2026-18262 · Severity: high · CVSS 7.8 · Published 2026-08-20

Technologies: Parallels RAS Client. Vendors: Parallels.

Executive brief

Parallels RAS Client is a remote access solution that enables users to connect to systems securely. A local privilege escalation vulnerability in the RDP Backend Service allows an attacker who already has low-level access to the system to escalate to SYSTEM-level privileges and execute arbitrary code, potentially compromising the entire system.

Technical details

This vulnerability exists in the Parallels RAS Client RDP Backend Service and results from an exposed dangerous function that can be abused for privilege escalation. The flaw requires the attacker to first obtain local code execution with low privileges (local attack vector). By leveraging the exposed function, an attacker can escalate privileges and execute arbitrary code in the SYSTEM security context. The vulnerability was fixed in version 21.2 of Parallels RAS Client.

Affected products

  • Parallels RAS Client before 21.2

Timeline

  • 2026-02-25: disclosed
  • 2026-08-11: advisory
  • 2026-08-11: patched: Fixed in version 21.2

References

Related threats