CVE-2024-54189: High severity parallels vulnerability
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard link, an attacker can write to an arbitrary file, potentially leading to privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54189?
CVE-2024-54189 is categorized as a privilege escalation vulnerability with a significant impact on system security.
How do I fix CVE-2024-54189?
To mitigate CVE-2024-54189, update Parallels Desktop for Mac to the latest version where the vulnerability is patched.
Who is affected by CVE-2024-54189?
CVE-2024-54189 affects users of Parallels Desktop for Mac version 20.1.1 (build 55740) and potentially earlier versions.
What can an attacker do with CVE-2024-54189?
An attacker exploiting CVE-2024-54189 can escalate privileges to write to arbitrary files, compromising system integrity.
Is there a public exploit for CVE-2024-54189?
As of now, there is no confirmed public exploit available for CVE-2024-54189, but users should remain vigilant.