Privilege Escalation Vulnerability in Parallels Desktop for Mac
CVE-2024-54189

7.8HIGH

Key Information:

Vendor

Parallels

Vendor
CVE Published:
3 June 2025

What is CVE-2024-54189?

A privilege escalation vulnerability has been identified in the Snapshot feature of Parallels Desktop for Mac. This issue arises when a virtual machine snapshot is created, leading to a root service that inadvertently writes to a file owned by a standard user. Exploiting this flaw, an attacker can leverage hard links to manipulate and write to arbitrary files, which can result in unauthorized escalation of privileges.

Affected Version(s)

Parallels Desktop for Mac version 20.1.1 (55740)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by KPC of Cisco Talos.
.