Unity Parsec
cpe:2.3:a:unity:parsec:*:*:*:*:*:*:*
- < 150-104a
A vulnerability allowing elevation of privilege has been identified in Unity Parsec for Windows, affecting versions prior to 150-104a. The issue arises from an incorrect use of privileged APIs, where a user can manipulate the AppData environment variable to create a situation where 'parsecd.exe' runs as 'NT AUTHORITY\SYSTEM'. This vulnerability can be exploited by authenticated users who have Parsec installed using the 'Per User' option.
Exploitation of this vulnerability allows for elevation of privilege, with the potential to execute code remotely as the 'SYSTEM' user, read arbitrary files as 'SYSTEM', and capture the NTLM hash of the 'SYSTEM' account.
To reproduce this vulnerability, install Parsec for Windows using the 'Per User' option. Once installed, connect to the target system and ensure that 'parsecd.exe' is running as 'NT AUTHORITY\SYSTEM'. This can be verified by checking the process details in the Task Manager. The vulnerability can be exploited by sending a command through the named pipe 'PARSEC-NP' to spawn a new instance of 'parsecd.exe' with a user-controlled AppData path. This can be done by updating the shared buffer that 'parsecd.exe' reads before launching the process. After the instance is spawned, the AppData path can be set to a location that triggers the desired actions, such as copying files or sending authentication hashes.
Users can update to Parsec for Windows version 150-104a or later. Instructions for updating are available on the Parsec support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.