CVE-2023-50226

Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Updater service. By creating a symbolic link, an attacker can abuse the service to move arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. . Was ZDI-CAN-21227.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:parallels:parallels_desktop:*:*:*:*:*:macos:*:*
cpe:2.3:a:parallels:parallels_desktop:*:*:*:*:*:macos:*:*

History

08 Aug 2025, 18:43

Type Values Removed Values Added
References () https://www.zerodayinitiative.com/advisories/ZDI-23-1805/ - () https://www.zerodayinitiative.com/advisories/ZDI-23-1805/ - Third Party Advisory
References () https://kb.parallels.com/en/125013 - () https://kb.parallels.com/en/125013 - Vendor Advisory
CPE cpe:2.3:a:parallels:parallels_desktop:*:*:*:*:*:macos:*:*
First Time Parallels parallels Desktop
Parallels

18 Sep 2024, 19:15

Type Values Removed Values Added
Summary Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Updater service. By creating a symbolic link, an attacker can abuse the service to move arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-21227. Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Updater service. By creating a symbolic link, an attacker can abuse the service to move arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. . Was ZDI-CAN-21227.

03 May 2024, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-03 03:16

Updated : 2025-08-08 18:43


NVD link : CVE-2023-50226

Mitre link : CVE-2023-50226


JSON object : View

Products Affected

parallels

  • parallels_desktop
CWE

No CWE.