Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47368 | Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system. |
Fixes
Solution
The vulnerability has been fixed by the manufacturer Parallels in version 19.3.0.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:33:05.241Z
Reserved: 2024-06-21T06:53:37.612Z
Link: CVE-2024-6240
Updated: 2024-08-01T21:33:05.241Z
Status : Modified
Published: 2024-06-21T14:15:14.240
Modified: 2024-11-21T09:49:15.750
Link: CVE-2024-6240
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD