A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Parallels
Parallels parallels Desktop |
|
CPEs | cpe:2.3:a:parallels:parallels_desktop:20.2.2_\(55879\):*:*:*:*:macos:*:* | |
Vendors & Products |
Parallels
Parallels parallels Desktop |
Tue, 03 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 03 Jun 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 03 Jun 2025 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation. | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: talos
Published: 2025-06-03T09:43:25.931Z
Updated: 2025-06-03T13:27:26.786Z
Reserved: 2025-03-28T15:54:45.505Z
Link: CVE-2025-31359

Updated: 2025-06-03T11:03:08.458Z

Status : Analyzed
Published: 2025-06-03T10:15:22.240
Modified: 2025-07-02T14:47:25.547
Link: CVE-2025-31359

No data.