CVE-2025-0413

CVSS 3.0 Score 7.8 of 10 (high)

Details

Published Feb 5, 2025
CWE ID 59

Summary

CVE-2025-0413 is a local privilege escalation vulnerability affecting Parallels Desktop. An attacker must initially gain the ability to execute low-privileged code on the target system to exploit this flaw. The issue lies within the Technical Data Reporter component, where an attacker can create a symbolic link to manipulate the service and modify the permissions of arbitrary files. Ultimately, this vulnerability enables an attacker to escalate privileges and execute arbitrary code with root access. (ZDI-CAN-25014)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share