Alludo Parallels Desktop
cpe:2.3:a:parallels:parallels_desktop:*:*:*:*:*:*:*, +3 more
- < 19.4.2
A privilege escalation vulnerability allowing users to gain root access has been identified in Alludo Parallels Desktop versions prior to 19.4.2 and in the 20.x series prior to 20.2.2. This vulnerability affects macOS on Intel platforms and arises during the virtual machine creation process.
Exploitation of this vulnerability allows a user with access to the Mac, but without root privileges, to gain root access by manipulating the Parallels Desktop virtual machine creation routine.
Users are advised to update Parallels Desktop to version 20.2.2 or 19.4.2. Instructions for updating can be found in the Parallels Desktop application under 'Check for updates'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.