Two different exploits for an unpatched Parallels Desktop privilege elevation vulnerability have been publicly disclosed, allowing users to gain root access on impacted Mac devices. Parallels Desktop is a virtualization software that allows Mac users to run Windows, Linux, and other operating systems alongside macOS. It is very popular among developers, businesses, and casual users who need Windows applications on their Macs without rebooting. Security researcher Mickey Jin published the exploits last week, demonstrating a bypass of the vendor's fixes for CVE-2024-34331, a privilege elevation flaw fixed in September. That flaw, first discovered in May 2024 by Mykola Grymalyuk, stemmed from a lack of code signature verification in Parallels Desktop for Mac. Jin says he released the exploits for the zero-day patch bypass after the developer allegedly left it unfixed for over seven months. "Given that the vendor has left this vulnerability unaddressed for over seven months—despite prior disclosure—I have chosen to publicly disclose this 0-day exploit," explains Jin in a technical writeup. "My goal is to raise awareness and urge users to mitigate risks proactively, as attackers could leverage this flaw in the wild." Parallels' original patch attempted to prevent untrusted code execution by verifying whether the 'createinstallmedia' tool is Apple-signed before granting it root privileges. However, Jin demonstrated that this verification is flawed, allowing attackers to bypass it ...
Exploits for unpatched Parallels Desktop flaw give root on Macs
BleepingComputer
·Bill Toulas
·Published Feb 24, 2025
·Updated
Affected Software
3 affected components
Parallels Desktop=20.2.1
Parallels Desktop=19.4.0
Parallels Desktop
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a privilege elevation vulnerability in Parallels Desktop that allows unauthorized root access on Macs.
2
What security implications are discussed?
The unpatched vulnerability could lead to significant security risks as attackers can exploit it to gain root access to affected Mac devices.
3
What versions of Parallels Desktop are affected?
The affected versions of Parallels Desktop are 20.2.1 and 19.4.0.
4
How were the exploits for the vulnerability made public?
Two different exploits for the privilege escalation flaw were publicly disclosed, raising concerns among users and security experts.
5
What should users of Parallels Desktop do in light of this vulnerability?
Users should monitor for updates from Parallels and apply patches as soon as they are available to protect against potential exploits.