Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5f6-gmwc-2843

Опубликовано: 21 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.

EPSS

Процентиль: 33%
0.00133
Низкий

7.7 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.7
nvd
больше 1 года назад

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.

EPSS

Процентиль: 33%
0.00133
Низкий

7.7 High

CVSS3

Дефекты

CWE-269