ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 20CVE-2026-18262
AI summary · glm-5.3

ZDI discloses CVE-2026-18262, a CVSS 7.8 exposed dangerous function in Parallels RAS Client's RDP backend service allowing local privilege escalation.

ZDI advisory ZDI-26-555 describes an exposed dangerous function in the Parallels RAS Client RDP backend service, tracked as CVE-2026-18262 with a CVSS score of 7.8. The flaw allows local attackers to escalate privileges on affected installations. Exploitation requires first obtaining the ability to execute low-privileged code on the target system.

  • CVE-2026-18262: exposed dangerous function in Parallels RAS Client RDP backend service
  • CVSS 7.8 local privilege escalation
  • Requires prior low-privileged code execution on target

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18262
Local Privilege Escalation in Parallels RAS Client RDP Backend Service

CVE-2026-18262 is a local privilege escalation vulnerability in the RDP Backend Service of the Parallels RAS (Remote Application Server) Client, reported through the Zero Day Initiative (ZDI-CAN-28885 / ZDI-26-555). The service exposes a dangerous function, and an attacker who can already execute low-privileged code on the affected machine can abuse it to gain elevated execution. Successful exploitation yields arbitrary code execution in the context of SYSTEM, giving the attacker full control of the host. Only systems with the Parallels RAS Client installed are affected; because SYSTEM is a Windows service context and a local foothold is required, this is a post-compromise escalation risk rather than a remote entry point. As of publication there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.1% probability of exploitation within 30 days, so no exploitation is known.

Do: Inventory endpoints running the Parallels RAS Client and apply the vendor fix referenced in the ZDI advisory ZDI-26-555 once Parallels identifies the patched release (no fixed version number is provided in this disclosure). Until patching, reduce the ability of users and untrusted software to run low-privileged code on hosts with the client installed, and monitor the RAS RDP Backend service for anomalous child processes or unexpected behavior. No workaround or public exploit is currently known.

7.8<1%
  • Parallels RAS Client (Remote Application Server Client), RDP Backend Service
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18262.

This source does not provide full text. Read it at zerodayinitiative.com.