VYPR
High severity7.0NVD Advisory· Published Aug 20, 2023· Updated Jun 17, 2026

CVE-2023-37250

CVE-2023-37250

Description

Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:unity:parsec:*:*:*:*:*:*:*:*
    Range: <9.0
  • Unity/Parsec Loaderdescription
  • Unity8/Unity8llm-fuzzy
    Range: <=8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.