Critical Local Privilege Escalation (CVE‑2026‑18262) in Parallels RAS Client RDP Backend Service
What It Is — Parallels RAS Client’s RDP backend service contains an exposed dangerous function that allows a local attacker to elevate privileges to the SYSTEM account. The flaw is tracked as CVE‑2026‑18262 and carries a CVSS 7.8 (High).
Exploitability — An attacker must first obtain the ability to run low‑privileged code on the target machine; no public exploit code is known, but the escalation path is trivial once foothold is achieved.
Affected Products — Parallels RAS Client (all versions prior to 21.2).
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous monitoring of patch status against SOC 2 CC6.1 (Logical Access Controls).
- Highlights the importance of least‑privilege configurations and documented privileged‑access reviews.
- Provides audit‑ready evidence that a vendor’s vulnerability‑management process is being tracked and remediated in a timely fashion.
Recommended Actions
- Upgrade all Parallels RAS Client installations to version 21.2 or later.
- Verify that the RDP backend service runs with the minimum required privileges; enforce least‑privilege.
- Capture patch‑deployment logs as SOC 2 evidence and map the remediation to the “System and Communications Protection” control.
- Enable endpoint detection to alert on any attempts to invoke the vulnerable function.
Source: Zero Day Initiative Advisory