PT-2026-55661 · Unity · Unity Parsec
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Unity Parsec versions prior to 150-104a
Description
An incorrect use of privileged APIs in Unity Parsec on Windows hosts allows for a potential elevation of privilege. This occurs when a user creates a scenario where an instance of the
parsecd.exe process runs as NT AUTHORITYSYSTEM while utilizing a user-controlled value of the AppData environment variable.Recommendations
Update to version 150-104a.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unity Parsec