Impact
The flaw is a local privilege escalation in Parallels RAS Client's RDP Backend Service that exposes a dangerous function. An attacker who can execute low‑privileged code locally can use this function to gain SYSTEM privileges and run arbitrary code. The vulnerability is a typical privilege escalation issue identified as CWE‑749.
Affected Systems
The vulnerability affects installations of Parallels RAS Client that include the RDP Backend Service. No specific affected versions are listed in the advisory, so all recent versions that contain the service should be considered vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity flaw. EPSS data is not available, but the vulnerability requires local code execution as a prerequisite, so the threat is localized to attackers who already have access to run low‑privileged processes on the target system. The flaw is not listed in the CISA KEV catalog, and no exploit is currently known, but the privilege escalation path allows an attacker to reach SYSTEM level, making it a serious risk for systems with exposed local code‑execution capabilities.
OpenCVE Enrichment