CVE-2023-37250: Unity Parsec
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.
Affected products
- Unity Parsec: before 9.0 (fixed in 9.0)
Published 2023-08-20. Last modified 2026-06-17.