{"id":"CVE-2026-54424","title":"An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege","summary":"An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. …","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-648"],"published":"2026-07-04","updated":"2026-07-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54424","references":[{"url":"https://github.com/tomadimitrie/CVE-2026-54424","label":"cve@mitre.org"},{"url":"https://parsec.app/","label":"cve@mitre.org"},{"url":"https://support.parsec.app/hc/en-us/articles/50612943726612-CVE-2026-54424","label":"cve@mitre.org"},{"url":"https://www.tomadimitrie.dev/blog/CVE-2026-54424","label":"cve@mitre.org"}],"tags":["nvd","exploit-available"],"epss":0.00185,"epssPercentile":0.07184,"ingestedAt":"2026-07-04T21:57:46.821Z","exploits":{"github":1,"githubRepos":["https://github.com/tomadimitrie/CVE-2026-54424"],"checkedAt":"2026-09-25T08:21:02.675Z"},"exploitAvailable":true,"slug":"CVE-2026-54424","body":"## Overview\n\nAn Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\\SYSTEM with a user-controlled value of the AppData environment variable.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":58,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":5341,"id":"CVE-2026-54424","ts":1788887267662,"field":"exploit_available","old":"false","new":"true"},{"seq":4224,"id":"CVE-2026-54424","ts":1788886383342,"field":"exploit_available","old":"true","new":"false"},{"seq":2980,"id":"CVE-2026-54424","ts":1788883047274,"field":"exploit_available","old":"false","new":"true"},{"seq":2009,"id":"CVE-2026-54424","ts":1788882451624,"field":"exploit_available","old":"true","new":"false"},{"seq":1085,"id":"CVE-2026-54424","ts":1788881888273,"field":"exploit_available","old":"false","new":"true"}]}