CVE-2025-0413
CVSS 3.0 Score 7.8 of 10 (high)
Details
Published Feb 5, 2025
CWE ID 59
Summary
CVE-2025-0413 is a local privilege escalation vulnerability affecting Parallels Desktop. An attacker must initially gain the ability to execute low-privileged code on the target system to exploit this flaw. The issue lies within the Technical Data Reporter component, where an attacker can create a symbolic link to manipulate the service and modify the permissions of arbitrary files. Ultimately, this vulnerability enables an attacker to escalate privileges and execute arbitrary code with root access. (ZDI-CAN-25014)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Desktop
Affected Vendors
- Docker Inc.