Privilege Escalation Vulnerability in Parallels Desktop Software
CVE-2024-6240
10CRITICAL
What is CVE-2024-6240?
A vulnerability in Parallels Desktop Software allows for improper privilege management, affecting versions before 19.3.0. Through this flaw, an attacker can inject malicious code into a script and manipulate the BASH_ENV environment variable to point to the compromised script. As a result, the malicious code may execute upon application startup, leading to potential privilege escalation on the system. This creates significant security implications for users operating older versions of the software, necessitating immediate action to update and secure affected systems.
Affected Version(s)
Parallels Desktop 0 < 19.3.0