ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
ZDI advisory discloses Parallels RAS Client RDP backend service local privilege escalation (CVE-2026-13121, CVSS 7.8).
ZDI advisory ZDI-26-554 describes an exposed dangerous function vulnerability in the RDP backend service of Parallels RAS Client, tracked as CVE-2026-13121 with a CVSS score of 7.8. Local attackers with the ability to execute low-privileged code can escalate privileges on affected installations.