Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

Summary

A flaw in Parallels Desktop for Mac allows non-administrator users to gain root access on a machine. While a fix exists in version 27, Intel Mac users are unable to install it, leaving them vulnerable.

IFF Assessment

FOE

The vulnerability allows unauthorized users to gain privileged root access, which is detrimental to system security and defenders.

Severity

7.8 High (AI Estimated)

The vulnerability allows for local privilege escalation, granting root access, which has a high impact on confidentiality, integrity, and availability. The attack requires local access but no authentication.

Defender Context

This vulnerability highlights the importance of promptly patching software, especially virtualization tools that often run with elevated privileges. Defenders should be aware of potential privilege escalation vectors and ensure all systems, including those with Intel processors, are updated to the latest secure versions of their software. Monitoring for unusual root-level activity could also help detect exploitation.

Read Full Story →