Логотип exploitDog
bind:CVE-2023-27328
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-27328

Количество 3

Количество 3

nvd логотип

CVE-2023-27328

почти 2 года назад

Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of a user-supplied string before using it to construct an XML document. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-19187.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-h2gx-393w-gcmp

почти 2 года назад

Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of a user-supplied string before using it to construct an XML document. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-19187.

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2023-08487

около 3 лет назад

Уязвимость компонента Toolgate гипервизора Parallels Desktop, позволяющая нарушителю выполнить произвольный код и повысить свои привилегии

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-27328

Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of a user-supplied string before using it to construct an XML document. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-19187.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-h2gx-393w-gcmp

Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of a user-supplied string before using it to construct an XML document. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-19187.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2023-08487

Уязвимость компонента Toolgate гипервизора Parallels Desktop, позволяющая нарушителю выполнить произвольный код и повысить свои привилегии

CVSS3: 7.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу