CVE-2024-6240

HIGH

Parallels Desktop Software <19.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.

Scores

CVSS v3 7.7
EPSS 0.0032
EPSS Percentile 23.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
parallels/parallels_desktop < 19.3.0
Published Jun 21, 2024
Tracked Since Feb 18, 2026