Privilege Escalation Vulnerability in Alludo Parallels Desktop for macOS
CVE-2025-30074

7.8HIGH

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 March 2025

What is CVE-2025-30074?

A vulnerability in Alludo Parallels Desktop for macOS allows attackers to escalate their privileges to root level through an exploit in the virtual machine creation routine. This flaw affects versions prior to 19.4.2 and 20.x before 20.2.2 on Intel platforms, presenting a significant risk for system integrity and user data security.

Affected Version(s)

Parallels Desktop 19.3.1 < 19.4.2

Parallels Desktop 20.0.0 < 20.2.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30074 : Privilege Escalation Vulnerability in Alludo Parallels Desktop for macOS