CVE-2023-37250
Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-367
- Affected
- unity/parsec
- Source
- cve@mitre.org
References
- https://support.parsec.app/hc/en-us/articles/18311425588237-CVE-2023-37250Third Party Advisory
- https://unity3d.comProduct
- https://www.kb.cert.org/vuls/id/287122Third Party Advisory, US Government Resource
- https://support.parsec.app/hc/en-us/articles/18311425588237-CVE-2023-37250Third Party Advisory
- https://unity3d.comProduct
- https://www.kb.cert.org/vuls/id/287122Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.