We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.
Reserved 2025-03-28 | Published 2025-06-03 | Updated 2025-06-03 | Assigner talosCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Discovered by KPC of Cisco Talos.
talosintelligence.com/vulnerability_reports/TALOS-2025-2160
Support options