A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.
History

Wed, 02 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Parallels
Parallels parallels Desktop
CPEs cpe:2.3:a:parallels:parallels_desktop:20.2.2_\(55879\):*:*:*:*:macos:*:*
Vendors & Products Parallels
Parallels parallels Desktop

Tue, 03 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Jun 2025 11:30:00 +0000


Tue, 03 Jun 2025 10:00:00 +0000

Type Values Removed Values Added
Description A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published: 2025-06-03T09:43:25.931Z

Updated: 2025-06-03T13:27:26.786Z

Reserved: 2025-03-28T15:54:45.505Z

Link: CVE-2025-31359

cve-icon Vulnrichment

Updated: 2025-06-03T11:03:08.458Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-03T10:15:22.240

Modified: 2025-07-02T14:47:25.547

Link: CVE-2025-31359

cve-icon Redhat

No data.