Executive brief
Parallels RAS Client is a remote access solution that enables users to connect to systems remotely via RDP. A local privilege escalation vulnerability in the RDP Backend Service allows an attacker with low-privileged code execution to gain SYSTEM-level privileges, potentially compromising the entire system and enabling lateral movement within a network.
Technical details
This vulnerability exists in the Parallels RAS Client RDP Backend Service, where an exposed dangerous function can be leveraged for privilege escalation. The flaw requires local code execution as a prerequisite; an attacker must already have the ability to run low-privileged code on the target system. By exploiting this exposed function, an attacker can escalate privileges to the SYSTEM context and execute arbitrary code with the highest privileges. The issue was fixed in RAS Client version 21.2 and has been assigned CVE-2026-18263 (CVSS 7.8).
Affected products
- Parallels RAS Client
Timeline
- 2026-02-25: disclosed: Vulnerability reported to vendor
- 2026-08-11: patched: Fixed in RAS Client version 21.2
- 2026-08-11: advisory: Coordinated public disclosure as ZDI-26-556