Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.4
CVE-2026-54424: Parsec on Windows: Elevation of Privilege via Malicious AppData
CVE-2026-54424
CVE-2026-54424
Summary
A vulnerability in Parsec for Windows allows a malicious user to potentially gain elevated system privileges. This could happen if a user controls the AppData environment variable, which is a setting that stores user-specific data. To fix this issue, update to the latest version of Parsec for Windows, version 150-104a, which includes a patch for this vulnerability.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unity | parsec | <= v2026-05-04.0 |
Original title
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version ...
Original description
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment variable.
mitre CVSS3.1
8.4
Vulnerability type
CWE-648
Published: 4 Jul 2026 · Updated: 20 Jul 2026 · First seen: 4 Jul 2026