Improper privilege management vulnerability in Parallels...
High severity
Unreviewed
Published
Jun 21, 2024
to the GitHub Advisory Database
•
Updated Jun 21, 2024
Description
Published by the National Vulnerability Database
Jun 21, 2024
Published to the GitHub Advisory Database
Jun 21, 2024
Last updated
Jun 21, 2024
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.
References