Local Privilege Escalation Vulnerability in Parallels Desktop by Parallels
CVE-2021-34857
8.2HIGH
What is CVE-2021-34857?
This vulnerability in Parallels Desktop versions allows local attackers to escalate their privileges due to insufficient validation of user-supplied data in the Toolgate component. By leveraging this flaw, an attacker can execute arbitrary code within the hypervisor context, assuming they first navigate past existing security measures on the guest system. This poses significant risks to system integrity and user data.
Affected Version(s)
Desktop 16.1.3 (49160)
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anonymous