AI analysis
CVE-2026-18263 is a local privilege escalation flaw in the RAS RDP Backend Service component of the Parallels RAS Client, caused by an exposed dangerous function (CWE-749). An attacker who has already gained the ability to run low-privileged code on the target machine can invoke this exposed function in the service. Successful exploitation yields arbitrary code execution in the context of SYSTEM, giving the attacker full control of the host. Any organization running the Parallels RAS Client on end-user or shared Windows hosts, typically in virtual desktop/remote application deployments, is potentially affected. The issue was disclosed through Trend Micro ZDI (ZDI-CAN-28886, ZDI-26-556); no public proof-of-concept is known, it is not in CISA KEV, and EPSS puts exploitation probability at ~0.1% over the next 30 days.
What to do: Inventory endpoints and shared hosts running the Parallels RAS Client (look for the RAS RDP Backend Service) and upgrade to the patched release cited in the Parallels/ZDI advisory for ZDI-26-556, since the fixed version is not stated in the available data. Until patched, limit low-privileged users' ability to launch arbitrary code on machines with the client installed, prioritizing multi-user/RDS and VDI hosts where a SYSTEM-level compromise has the widest reach. With no public PoC, KEV listing, or known in-the-wild exploitation, this is a routine patch-cycle item except on shared RAS hosts.
Affected
| Parallels RAS Client (RAS RDP Backend Service component) | — |
Estimated exposure
largelikely tens of thousands of managed Windows endpoints with the Parallels RAS Client installed (order-of-magnitude estimate; no public install counts) — No public install or scan counts exist for this product, so the estimate is based on deployment patterns: the RAS Client is pushed to end-user workstations and shared hosts in enterprise virtual desktop/remote-application deployments…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28886.