Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47368 Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.
Fixes

Solution

The vulnerability has been fixed by the manufacturer Parallels in version 19.3.0.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T21:33:05.241Z

Reserved: 2024-06-21T06:53:37.612Z

Link: CVE-2024-6240

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.241Z

cve-icon NVD

Status : Modified

Published: 2024-06-21T14:15:14.240

Modified: 2024-11-21T09:49:15.750

Link: CVE-2024-6240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.