Filtered by vendor Parallels Subscriptions
Total 145 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-34892 1 Parallels 1 Parallels Desktop 2024-08-03 7.8 High
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update machanism. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-16396.
CVE-2022-34890 1 Parallels 1 Parallels Desktop 2024-08-03 8.8 High
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Parallels Tools component. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-16653.
CVE-2022-30777 1 Parallels 1 H-sphere 2024-08-03 6.1 Medium
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
CVE-2023-45894 1 Parallels 1 Remote Application Server 2024-08-02 10.0 Critical
The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.
CVE-2024-6240 1 Parallels 1 Parallels Desktop 2024-08-01 7.7 High
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.