Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Local Privilege Escalation (CVE-2026-13121) in Parallels RAS Client RDP Backend Service

Parallels RAS Client’s RDP Backend Service contains a local privilege escalation flaw (CVE‑2026‑13121) that can let low‑privileged code run as SYSTEM. The issue underscores the need for continuous patch‑management and access‑control evidence to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Local Privilege Escalation (CVE‑2026‑13121) in Parallels RAS Client RDP Backend Service

What It Is — Parallels RAS Client contains a local privilege escalation flaw (CVE‑2026‑13121) in its RDP Backend Service that lets a low‑privileged attacker execute code as SYSTEM.

Exploitability — Requires attacker‑controlled low‑privileged code; no public exploit yet, CVSS 7.8 (High).

Affected Products — Parallels RAS Client (all versions prior to 21.2).

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for continuous patch‑management evidence under SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
  • Highlights the importance of least‑privilege access controls (CC6.2) and monitoring for unexpected privilege‑escalation events.
  • Enterprise buyers increasingly demand proof that remote‑access solutions are hardened and that remediation is tracked in real time.

Recommended Actions — 1. Upgrade to Parallels RAS Client 21.2 or later. 2. Verify patch deployment via automated inventory. 3. Review and tighten local admin rights on workstations running the client. 4. Enable logging of privilege‑escalation events and map to SOC 2 controls. Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-554/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →