Impact
The flaw enables a local attacker to elevate privileges within the RAS RDP Backend Service. The exposed function is callable by low‑privileged code and allows the attacker to execute arbitrary code as SYSTEM. Even though initial access is required, once obtained the attacker could bypass all system controls. This is a classic unchecked input flaw leading to full system compromise.
Affected Systems
The vulnerability affects Parallels RAS Client installations that include the RDP Backend Service. No specific version numbers are documented, so all deployments using this component should be considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS is not available, and the vulnerability is not in CISA KEV. Because the exploit requires local code execution, the attack surface is limited to users with some degree of local access. Nevertheless, once the attacker gains that foothold, the risk of system compromise is significant.
OpenCVE Enrichment