Local Privilege Escalation in Parallels Desktop by Parallels
CVE-2021-34868
7.8HIGH
What is CVE-2021-34868?
This vulnerability in Parallels Desktop allows local attackers to escalate privileges after gaining the capability to execute low-privileged code on the guest system. The flaw is found in the Toolgate component, stemming from inadequate validation of user-supplied data, leading to uncontrolled memory allocation. This defect could permit attackers to escalate their privileges and run arbitrary code within the hypervisor context, posing significant security risks.
Affected Version(s)
Desktop 16.1.3-49160
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Reno Robert of Trend Micro Zero Day Initiative