Impact
Parallels Desktop hosts a root‑privileged daemon, prl_disp_service, that listens on a world‑writable Unix socket. The service accepts local login requests and allows untrusted users to specify the path of an appliance to install. The daemon constructs a tar command using the supplied path without proper sanitization; a quote in the path causes the command string to be split incorrectly, allowing an attacker to inject unintended tar options. Because macOS’s tar can execute a specified compression program as root, the attacker can run arbitrary commands with root privileges whenever a local user requests an appliance extraction.
Affected Systems
Products affected are Parallels Desktop for Mac. The vulnerability exists before the release of Parallels Desktop 27.0.0, which contains the fix.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local exploitation scenario. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of a KEV listing does not preclude active attacks. The attack vector is local; any user who can run the Parallels client can trigger the vulnerable routine and obtain root privileges on the host. The vulnerability stems from improper with elevated rights (CWE‑78), and command injection via arbitrary filesystem paths (CWE‑88).
OpenCVE Enrichment