Critical Local Privilege Escalation (CVE‑2026‑13121) in Parallels RAS Client RDP Backend Service
What It Is — Parallels RAS Client contains a local privilege escalation flaw (CVE‑2026‑13121) in its RDP Backend Service that lets a low‑privileged attacker execute code as SYSTEM.
Exploitability — Requires attacker‑controlled low‑privileged code; no public exploit yet, CVSS 7.8 (High).
Affected Products — Parallels RAS Client (all versions prior to 21.2).
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous patch‑management evidence under SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
- Highlights the importance of least‑privilege access controls (CC6.2) and monitoring for unexpected privilege‑escalation events.
- Enterprise buyers increasingly demand proof that remote‑access solutions are hardened and that remediation is tracked in real time.
Recommended Actions — 1. Upgrade to Parallels RAS Client 21.2 or later. 2. Verify patch deployment via automated inventory. 3. Review and tighten local admin rights on workstations running the client. 4. Enable logging of privilege‑escalation events and map to SOC 2 controls. Source: Zero Day Initiative advisory