CVE-2022-34899: Parallels Access Agent Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-16134.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34899?
CVE-2022-34899 is a vulnerability that allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent.
How can the CVE-2022-34899 vulnerability be exploited?
To exploit CVE-2022-34899, an attacker must first obtain the ability to execute low-privileged code on the target host system.
What is the affected software for CVE-2022-34899?
The affected software for CVE-2022-34899 is Parallels Access 6.5.4 (39316) Agent.
How severe is the vulnerability CVE-2022-34899?
The severity of the vulnerability CVE-2022-34899 is high with a CVSS score of 7.8.
How can I fix the CVE-2022-34899 vulnerability?
To fix the CVE-2022-34899 vulnerability, it is recommended to update to the latest version of Parallels Access.