CVE-2026-13121: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-29220.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Parallels RAS Client RDP Backend Serviceto a version that resolves this vulnerability.Patch ZDI-CAN-29220
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems with an affected installation of Parallels RAS Client are exposed. Exploitation is local, so an attacker must already be able to run low-privileged code on the target system.
What level of access can an attacker gain?
An attacker can escalate privileges and execute arbitrary code in the context of SYSTEM. This can compromise confidentiality, integrity, and availability of the affected system.
Which component is affected?
The flaw is in the RAS RDP Backend Service. It results from an exposed dangerous function in that service.