Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-50227

8.3HIGH

Key Information:

Vendor

Parallels

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-50227?

A remote code execution vulnerability exists in the virtio-gpu component of Parallels Desktop, attributed to insufficient validation of user-supplied data during processing. This flaw allows an attacker to manipulate data in such a way that it results in a write operation that exceeds the bounds of a buffer. As a result, an attacker can execute arbitrary code in the context of the hypervisor, provided that a user on a guest system interacts with a malicious webpage or file. This presents a significant risk, especially in environments that utilize virtual machines for various purposes. Mitigating this vulnerability involves enforcing strict input validation and patching affected systems as per vendor advisories.

Affected Version(s)

Desktop 18.3.2 (53621)

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.