Privilege Escalation Vulnerability in Parallels Desktop Software
CVE-2024-6240

10CRITICAL

Key Information:

Vendor

Parallels

Vendor
CVE Published:
21 June 2024

What is CVE-2024-6240?

A vulnerability in Parallels Desktop Software allows for improper privilege management, affecting versions before 19.3.0. Through this flaw, an attacker can inject malicious code into a script and manipulate the BASH_ENV environment variable to point to the compromised script. As a result, the malicious code may execute upon application startup, leading to potential privilege escalation on the system. This creates significant security implications for users operating older versions of the software, necessitating immediate action to update and secure affected systems.

Affected Version(s)

Parallels Desktop 0 < 19.3.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Carlos Polop MartĂ­n
.
CVE-2024-6240 : Privilege Escalation Vulnerability in Parallels Desktop Software