Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability
CVE-2024-6153
What is CVE-2024-6153?
The vulnerability manifests due to a failure in the Updater service of Parallels Desktop, allowing local attackers to downgrade installed software versions. This issue arises from inadequate validation of version information during the update process. Attackers, having gained low-privileged access on the system, can exploit this flaw potentially in conjunction with other vulnerabilities to escalate their privileges. If successfully executed, this could lead to arbitrary code execution with elevated privileges, compromising system integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Desktop 18.1.0 (53311)
References
CVSS V3.1
Timeline
Vulnerability published
