CVE-2024-52561: high-severity vulnerability in Parallels Desktop for Mac
Published
No sign of exploitation. No public exploitation artifact known so far.
Parallels Desktop for Mac allows attackers to escalate privileges by exploiting a flaw in how snapshot files are deleted. When snapshots are removed, an attacker can use a symlink trick to change ownership of root-owned files to their user account, gaining higher privileges.
A privilege escalation vulnerability exists in Parallels Desktop 20.1.1 (build 55740) where the root service performing ownership modifications on snapshot deletion can be abused via symlink substitution (CWE-708). An attacker with local user access can redirect file operations to arbitrary paths, changing ownership of privileged files to lower-privilege accounts and achieving privilege escalation.
In the same product, most dangerous first.