AI analysis
CVE-2026-18262 is a local privilege escalation vulnerability in the RDP Backend Service of the Parallels RAS (Remote Application Server) Client, reported through the Zero Day Initiative (ZDI-CAN-28885 / ZDI-26-555). The service exposes a dangerous function, and an attacker who can already execute low-privileged code on the affected machine can abuse it to gain elevated execution. Successful exploitation yields arbitrary code execution in the context of SYSTEM, giving the attacker full control of the host. Only systems with the Parallels RAS Client installed are affected; because SYSTEM is a Windows service context and a local foothold is required, this is a post-compromise escalation risk rather than a remote entry point. As of publication there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.1% probability of exploitation within 30 days, so no exploitation is known.
What to do: Inventory endpoints running the Parallels RAS Client and apply the vendor fix referenced in the ZDI advisory ZDI-26-555 once Parallels identifies the patched release (no fixed version number is provided in this disclosure). Until patching, reduce the ability of users and untrusted software to run low-privileged code on hosts with the client installed, and monitor the RAS RDP Backend service for anomalous child processes or unexpected behavior. No workaround or public exploit is currently known.
Affected
| Parallels RAS Client (Remote Application Server Client), RDP Backend Service | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28885.