Local Privilege Escalation in Parallels Desktop by Parallels
CVE-2021-34868

7.8HIGH

Key Information:

Vendor

Parallels

Status
Vendor
CVE Published:
25 January 2022

What is CVE-2021-34868?

This vulnerability in Parallels Desktop allows local attackers to escalate privileges after gaining the capability to execute low-privileged code on the guest system. The flaw is found in the Toolgate component, stemming from inadequate validation of user-supplied data, leading to uncontrolled memory allocation. This defect could permit attackers to escalate their privileges and run arbitrary code within the hypervisor context, posing significant security risks.

Affected Version(s)

Desktop 16.1.3-49160

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reno Robert of Trend Micro Zero Day Initiative
.