CVE-2026-54424 is a local privilege-escalation vulnerability in Unity Parsec on Windows hosts. The issue is described as an incorrect use of privileged APIs that can result in an instance of parsecd.exe running as NT AUTHORITY\SYSTEM while using a user-controlled value of the AppData environment variable. This creates a condition where lower-privileged user-controlled input influences behavior in a SYSTEM-context process, enabling elevation of privilege. The issue affects Parsec through v2026-05-04.0 and is fixed in Parsec for Windows version 150-104a. Public proof-of-concept/exploit material is referenced in the provided content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real Windows local privilege-escalation exploit project for CVE-2026-54424 affecting Parsec for Windows versions earlier than 150-104a. It is a Visual Studio solution with two projects: a main console exploit in cve/ and a malicious DLL payload in exp/. The exploit is not part of a common framework. Repository structure: cve/main.cpp is the primary entry point and exposes three modes: mode 0 triggers Parsec update/launch behavior with attacker-controlled working directory content, mode 1 performs arbitrary file read by preparing a fake Parsec directory tree, sending an UPDATE command to Parsec, placing an oplock on a lock file, and replacing a copied skel directory with a junction/reparse point to an attacker-chosen target, and mode 2 performs RCE by staging multiple DLL variants and abusing Windows Cloud Files API callbacks to swap backing content during a tight race. Supporting modules include exploit_common.cpp for named-pipe interaction and remote thread injection into the Parsec process, ntfs_utils.cpp for junction creation and oplock handling, cfapi_utils.cpp for sync root/placeholder management, pe_utils.cpp for padding a PE Authenticode security directory to enlarge a DLL, and utils.cpp for locating the correct parsecd.exe process running as the current user. Main exploit capabilities: (1) arbitrary file read as SYSTEM by redirecting Parsec file access through a mount-point junction after winning an oplock race; (2) SYSTEM RCE by causing Parsec to load an attacker DLL, with the sample payload launching cmd.exe from DllMain; and (3) a launch/update primitive that sends an UPDATE command over the Parsec named pipe. The README also claims NTLM hash capture as another impact from the same vulnerability family, though no dedicated implementation for that is obvious in the provided code. Notable mechanics: the exploit injects a remote thread into parsecd.exe that opens \\.\pipe\PARSEC-NP and writes an UPDATE command containing C:\Program Files\Parsec\parsecd.exe and an attacker-controlled working directory. The RCE path creates a fake Parsec directory with orig.dll, blank_big.dll, padded.dll, appdata.json, and a cloud placeholder maybeparsec.dll. It registers a CfAPI sync root and uses FetchDataCallback/FileClosedCallback to dynamically serve different DLL contents as the placeholder is accessed, attempting to win a race during Parsec validation/loading. The included payload DLL is basic and hardcoded, so the exploit is best classified as OPERATIONAL rather than fully weaponized.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.