Privilege Escalation Vulnerability in Parallels Desktop Software
CVE-2024-6240
10CRITICAL
What is CVE-2024-6240?
A vulnerability in Parallels Desktop Software allows for improper privilege management, affecting versions before 19.3.0. Through this flaw, an attacker can inject malicious code into a script and manipulate the BASH_ENV environment variable to point to the compromised script. As a result, the malicious code may execute upon application startup, leading to potential privilege escalation on the system. This creates significant security implications for users operating older versions of the software, necessitating immediate action to update and secure affected systems.
Affected Version(s)
Parallels Desktop 0 < 19.3.0
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Carlos Polop MartĂn