📦 Parallels Desktop

by Parallels

🔍 What is Parallels Desktop?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-54189

HIGH CVSS 7.8 Jun 3, 2025

A privilege escalation vulnerability in Parallels Desktop for Mac allows attackers to write to arbitrary files by exploiting hard links during snapshot creation. This could enable local attackers to g...

CVE-2024-36486

HIGH CVSS 7.8 Jun 3, 2025

This CVE describes a privilege escalation vulnerability in Parallels Desktop for Mac where the prl_vmarchiver tool writes decompressed archive contents with root privileges. Attackers can exploit this...

CVE-2023-50226

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows local attackers with low-privileged access to escalate to root privileges by exploiting a symbolic link issue in Parallels Desktop's Updater service. Attackers can move arbit...

CVE-2023-50228

HIGH CVSS 7.8 May 3, 2024

This vulnerability in Parallels Desktop Updater allows local attackers to escalate privileges from low-privileged code execution to root-level access due to improper cryptographic signature verificati...

CVE-2023-27326

HIGH CVSS 8.2 May 3, 2024

This vulnerability allows local attackers with high-privileged code execution on a Parallels Desktop guest system to escalate privileges on the host system via directory traversal in the Toolgate comp...

CVE-2023-27328

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows local attackers on Parallels Desktop guest systems to escalate privileges by exploiting XML injection in the Toolgate component. Attackers must first execute low-privileged c...

CVE-2023-27322

HIGH CVSS 7.8 May 3, 2024

This vulnerability in Parallels Desktop Service allows local attackers with low-privileged access to escalate to root privileges due to improper environment variable initialization. It affects Paralle...

CVE-2023-27324

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows local attackers to escalate privileges on affected Parallels Desktop installations by exploiting improper initialization of environment variables in the Updater service. Atta...

CVE-2022-34889

HIGH CVSS 8.2 Jul 18, 2022

This vulnerability in Parallels Desktop allows local attackers with high-privileged code execution on a guest VM to escalate privileges to hypervisor level through a buffer read overflow in the ACPI v...

CVE-2022-34891

HIGH CVSS 7.8 Jul 18, 2022

CVE-2022-34891 is a local privilege escalation vulnerability in Parallels Desktop where incorrect file permissions allow attackers to escalate to root privileges. Attackers must first gain local code ...

CVE-2021-34987

HIGH CVSS 8.2 Jul 15, 2022

This is a buffer overflow vulnerability in Parallels Desktop's HDAudio virtual device that allows local attackers with high-privileged code execution on a guest system to escalate privileges to hyperv...

CVE-2021-34856

HIGH CVSS 8.8 Oct 25, 2021

This vulnerability in Parallels Desktop allows local attackers with high-privileged code execution on a guest system to escalate privileges to hypervisor level through memory corruption in the virtio-...

CVE-2021-31420

HIGH CVSS 8.8 Apr 29, 2021

This is a local privilege escalation vulnerability in Parallels Desktop's Toolgate component. Attackers with low-privileged access to a guest VM can exploit a stack-based buffer overflow to execute ar...

CVE-2021-31422

HIGH CVSS 7.5 Apr 29, 2021

This vulnerability allows local attackers with high-privileged code execution on a Parallels Desktop guest system to escalate privileges to hypervisor level through a race condition in the e1000e virt...

CVE-2021-31424

HIGH CVSS 8.8 Apr 29, 2021

This is a heap-based buffer overflow vulnerability in Parallels Desktop's Open Tools Gate component that allows local attackers to escalate privileges from guest systems to hypervisor level. Attackers...

CVE-2021-31426

HIGH CVSS 8.8 Apr 29, 2021

This vulnerability in Parallels Desktop allows local attackers with initial low-privileged access to escalate privileges to kernel-level execution through an integer overflow in the Parallels Tools co...

CVE-2021-31428

HIGH CVSS 8.2 Apr 29, 2021

This is a heap-based buffer overflow vulnerability in Parallels Desktop's IDE virtual device that allows local attackers with high-privileged code execution on a guest system to escalate privileges to...

CVE-2021-27242

HIGH CVSS 8.8 Mar 29, 2021

This vulnerability in Parallels Desktop allows local attackers with initial low-privileged access to a guest virtual machine to escalate privileges and execute arbitrary code in the hypervisor context...

CVE-2024-6154

MEDIUM CVSS 6.7 Jun 20, 2024

This is a heap-based buffer overflow vulnerability in Parallels Desktop's Toolgate component that allows local attackers to escalate privileges. Attackers who already have high-privileged code executi...