ZDI-25-473: Parallels Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2025-6812.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-473?
ZDI-25-473 has been assigned a CVSS rating indicating a significant vulnerability that allows for privilege escalation.
How do I fix ZDI-25-473?
To mitigate ZDI-25-473, ensure that Parallels Client is updated to the latest version provided by the vendor.
What type of vulnerability is ZDI-25-473?
ZDI-25-473 is a privilege escalation vulnerability that affects local installations of Parallels Client.
Who is affected by ZDI-25-473?
Local attackers with low-privileged access to systems running the affected versions of Parallels Client are at risk from ZDI-25-473.
What should I do if I am affected by ZDI-25-473?
If affected by ZDI-25-473, immediately update your Parallels Client software to the patched version to eliminate the risk.