ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

AI summary · glm-5.3

ZDI discloses Parallels RAS Client RDP backend service flaw (CVE-2026-18263, CVSS 7.8) letting local attackers escalate privileges.

ZDI advisory ZDI-26-556 covers an exposed dangerous function in the Parallels RAS Client's RDP backend service, tracked as CVE-2026-18263 with a CVSS rating of 7.8. A local attacker who can already execute low-privileged code on the target system can use the flaw to escalate privileges.

  • Parallels RAS Client RDP backend service privilege escalation
  • CVE-2026-18263 rated CVSS 7.8
  • Requires attacker to already have low-privileged code execution

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18263
Local Privilege Escalation to SYSTEM in Parallels RAS Client RDP Backend Service

CVE-2026-18263 is a local privilege escalation flaw in the RAS RDP Backend Service component of the Parallels RAS Client, caused by an exposed dangerous function (CWE-749). An attacker who has already gained the ability to run low-privileged code on the target machine can invoke this exposed function in the service. Successful exploitation yields arbitrary code execution in the context of SYSTEM, giving the attacker full control of the host. Any organization running the Parallels RAS Client on end-user or shared Windows hosts, typically in virtual desktop/remote application deployments, is potentially affected. The issue was disclosed through Trend Micro ZDI (ZDI-CAN-28886, ZDI-26-556); no public proof-of-concept is known, it is not in CISA KEV, and EPSS puts exploitation probability at ~0.1% over the next 30 days.

Do: Inventory endpoints and shared hosts running the Parallels RAS Client (look for the RAS RDP Backend Service) and upgrade to the patched release cited in the Parallels/ZDI advisory for ZDI-26-556, since the fixed version is not stated in the available data. Until patched, limit low-privileged users' ability to launch arbitrary code on machines with the client installed, prioritizing multi-user/RDS and VDI hosts where a SYSTEM-level compromise has the widest reach. With no public PoC, KEV listing, or known in-the-wild exploitation, this is a routine patch-cycle item except on shared RAS hosts.

7.8<1%
  • Parallels RAS Client (RAS RDP Backend Service component)
largelikely tens of thousands of managed Windows endpoints with the Parallels RAS Client installed (order-of-magnitude estimate; no public install counts)
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18263.

This source does not provide full text. Read it at zerodayinitiative.com.