← Back

CVE-2025-0413

nvd nist
Published: Feb 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: zdi-disclosures@trendmicro.com (Secondary)

Description

Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Technical Data Reporter component. By creating a symbolic link, an attacker can abuse the service to change the permissions of arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-25014.

Affected (3)

2 products
Remote Application Server
Parallels
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 19.4.3.2-25228
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Parallels
From 19.0-23304 to 19.4.3-25221
From 20.0-25389 to 20.2-25889

References (2)

Source: zdi-disclosures@trendmicro.com
Release Notes
Source: zdi-disclosures@trendmicro.com
Third Party Advisory

Timeline

No history available yet.