CVE-2025-30074
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 16, 2025
CWE ID 863
Summary
CVE-2025-30074 is a vulnerability affecting Alludo Parallels Desktop versions before 19.4.2 and 20.x before 20.2.2 on Intel macOS platforms. This issue permits privilege escalation, enabling an attacker to gain root access during the virtual machine creation process. Successful exploitation of this vulnerability could lead to significant security compromises and unauthorized system modifications. Users are strongly encouraged to update their Parallels Desktop software to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Parallels Desktop
Affected Vendors
- Parallels