Parallels Desktop
cpe:2.3:a:parallels:parallels_desktop:*:*:*:*:*:*:*, +3 more
- 20.2.2 (55879)
A directory traversal vulnerability has been identified in Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability arises in the PVMP package unpacking process, where an attacker can manipulate file paths to write to arbitrary files. Such exploitation could lead to unauthorized privilege escalation, as the `prl_disp_service` managing the unpacking operates with root privileges.
Exploitation of this vulnerability allows a low-privilege user to overwrite arbitrary files and escalate privileges to that of a root user.
The vulnerability can be reproduced by using the `prl_packer_inplace` executable to create a `.pvmp` package file that includes directory traversal characters in the file paths. Once the package is transferred and unpacked using Parallels Desktop, the traversed file paths are resolved, leading to the overwriting of files, such as launch daemons, with potentially malicious content.
Users are advised to update to the patched version of Parallels Desktop for Mac, which is available through the Parallels Desktop application or the Parallels website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.