Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability
CVE-2024-6153

7.8HIGH

Key Information:

Vendor

Parallels

Status
Vendor
CVE Published:
20 June 2024

What is CVE-2024-6153?

The vulnerability manifests due to a failure in the Updater service of Parallels Desktop, allowing local attackers to downgrade installed software versions. This issue arises from inadequate validation of version information during the update process. Attackers, having gained low-privileged access on the system, can exploit this flaw potentially in conjunction with other vulnerabilities to escalate their privileges. If successfully executed, this could lead to arbitrary code execution with elevated privileges, compromising system integrity and security.

Affected Version(s)

Desktop 18.1.0 (53311)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.