We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-54189



Description

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard link, an attacker can write to an arbitrary file, potentially leading to privilege escalation.

Reserved 2024-12-05 | Published 2025-06-03 | Updated 2025-06-03 | Assigner talos


HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-62: UNIX Hard Link

Product status

version 20.1.1 (55740)
affected

Credits

Discovered by KPC of Cisco Talos.

References

talosintelligence.com/vulnerability_reports/TALOS-2024-2124

cve.org (CVE-2024-54189)

nvd.nist.gov (CVE-2024-54189)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-54189

Support options

Helpdesk Chat, Email, Knowledgebase