Parsec Remote Desktop App is prone to a local elevation of privilege due to a logical flaw in its code integrity verific

Post Reply
Shane1145
Posts: 1689
Joined: Wed Sep 25, 2024 2:31 pm

Parsec Remote Desktop App is prone to a local elevation of privilege due to a logical flaw in its code integrity verific

Post by Shane1145 »

Parsec updater for Windows was prone to a local privilege escalation vulnerability, this vulnerability allowed a local user with Parsec access to gain NT_AUTHORITY/SYSTEM privileges.
The vulnerability is a time-of-check time–of-use (TOCTOU) vulnerability. There existed a small window between verifying the signature and integrity of the update DLL and the execution of DLL main.

https://www.kb.cert.org/vuls/id/287122
Post Reply