CVE-2023-37250: Unity Parsec

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.

Affected products

  • Unity Parsec: before 9.0 (fixed in 9.0)

Published 2023-08-20. Last modified 2026-06-17.