We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the snapshot files. By using a symlink, an attacker can change the ownership of files owned by root to a lower-privilege user, potentially leading to privilege escalation.
Reserved 2024-12-05 | Published 2025-06-03 | Updated 2025-06-03 | Assigner talosCWE-708: Incorrect Ownership Assignment
Discovered by KPC of Cisco Talos.
talosintelligence.com/vulnerability_reports/TALOS-2024-2123
Support options