CVE-2024-6240
HIGHParallels Desktop Software <19.3.0 - Privilege Escalation
Title source: llmDescription
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.
References (1)
Core 1
Core References
Scores
CVSS v3
7.7
EPSS
0.0032
EPSS Percentile
23.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (1)
parallels/parallels_desktop
< 19.3.0
Published
Jun 21, 2024
Tracked Since
Feb 18, 2026