Description
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-29220.
Published: 2026-08-20
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a local privilege escalation in Parallels RAS Client's RDP Backend Service that exposes a dangerous function. An attacker who can execute low‑privileged code locally can use this function to gain SYSTEM privileges and run arbitrary code. The vulnerability is a typical privilege escalation issue identified as CWE‑749.

Affected Systems

The vulnerability affects installations of Parallels RAS Client that include the RDP Backend Service. No specific affected versions are listed in the advisory, so all recent versions that contain the service should be considered vulnerable until a patch is released.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity flaw. EPSS data is not available, but the vulnerability requires local code execution as a prerequisite, so the threat is localized to attackers who already have access to run low‑privileged processes on the target system. The flaw is not listed in the CISA KEV catalog, and no exploit is currently known, but the privilege escalation path allows an attacker to reach SYSTEM level, making it a serious risk for systems with exposed local code‑execution capabilities.

Generated by OpenCVE AI on August 20, 2026 at 19:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update or patch for Parallels RAS Client that eliminates the exposed function.
  • Enforce the principle of least privilege on the system so that local code execution is restricted to trusted accounts only.
  • If the RDP Backend Service is not required in your environment, disable or uninstall it to remove the vulnerable component.

Generated by OpenCVE AI on August 20, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-29220.
Title Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
Weaknesses CWE-749
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-20T16:25:44.565Z

Reserved: 2026-06-23T22:08:03.592Z

Link: CVE-2026-13121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T17:17:20.787

Modified: 2026-08-20T17:17:20.787

Link: CVE-2026-13121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:00:05Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function