CVE-2025-31359

HIGH

Parallels Desktop for Mac 20.2.2 - Path Traversal and Arbitrary File Write via PVMP Package Unpacking

Title source: llm
STIX 2.1

Description

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0164
EPSS Percentile 73.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
parallels/parallels_desktop 20.2.2_\(55879\)
Published Jun 03, 2025
Tracked Since Feb 18, 2026