ZDI-22-947: Parallels Access Agent Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-22-947?
The vulnerability ZDI-22-947 is considered high severity as it allows local attackers to escalate privileges.
How do I fix ZDI-22-947?
To fix vulnerability ZDI-22-947, update Parallels Access to the latest version as provided by the vendor.
Who is affected by ZDI-22-947?
ZDI-22-947 affects installations of Parallels Access Agent on local systems.
What type of attack does ZDI-22-947 facilitate?
ZDI-22-947 facilitates local privilege escalation attacks on affected systems.
What must an attacker do to exploit ZDI-22-947?
An attacker must first execute low-privileged code on the target host system to exploit ZDI-22-947.