Junglewise Threat Intelligence

CVE-2026-54424: Unity Parsec privilege escalation via incorrect API use in Windows service

CVE-2026-54424 · Severity: high · CVSS 8.4 · Published 2026-07-04

Executive brief

Unity Parsec is a high-performance remote desktop and gaming application. A security flaw in the Windows version allows a local user to trick the software into running commands with the highest possible system privileges (NT AUTHORITY\SYSTEM). This could allow an attacker to take full control of the computer, steal sensitive data, or bypass security restrictions.

Technical details

The vulnerability exists in the Parsec service (pservice.exe), which runs as NT AUTHORITY\SYSTEM and exposes a named pipe (\\.\pipe\PARSEC-NP). While the service attempts to validate clients by checking the process path and Authenticode signature, it fails to verify the user identity, allowing an unprivileged user to inject code into a legitimate parsecd.exe instance to communicate with the pipe. An attacker can use the 'UPDATE' command via the pipe to set a user-controlled AppData path. When the service subsequently relaunches parsecd.exe as SYSTEM (due to a simulated crash or abnormal exit), it uses the attacker-controlled environment variable. This can be further exploited to achieve Remote Code Execution (RCE) via DLL hijacking, arbitrary file reads via TOCTOU races in the 'skel' folder self-healing logic, or NTLM hash capture. The issue is patched in version 150-104a.

Affected products

  • Unity Parsec for Windows through v2026-05-04.0

Timeline

  • 2026-04-13: disclosed: Initial researcher discovery/writeup date
  • 2026-07-04: advisory: NVD publication date

References