Vulnerabilidades en Parallels

80 resultados
Análisis Vexday

Com 80 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco imediato do Parallels situa-se abaixo da média geral do catálogo, sem registros de severidade crítica, PoCs públicas disponíveis ou novas vulnerabilidades nos últimos 90 dias. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que, embora não represente risco imediato elevado, costuma servir de base para cadeias de exploração mais complexas quando combinado com outras vulnerabilidades. A CVE de maior atenção no momento é CVE-2025-31359, com escore EPSS de 0,0168, indicando probabilidade de exploração ainda baixa no curto prazo. Equipes de segurança podem manter monitoramento de rotina, priorizando o controle de CVEs relacionadas a leituras de memória fora dos limites e acompanhando eventuais evoluções no EPSS de CVE-2025-31359.

CVE-2021-34868HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker muEPSS 0.4%CVE-2020-8874HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker muEPSS 0.4%CVE-2021-34869HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker muEPSS 0.4%CVE-2025-0413HIGHParallels Desktop Technical Data Reporter Link Following Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2023-27327HIGHParallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2021-31421LOWThis vulnerability allows local attackers to delete arbitrary files on affected installations of Parallels Desktop 16.1.1-49141. An attackerEPSS 0.4%CVE-2020-8873HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker muEPSS 0.4%CVE-2023-27322HIGHParallels Desktop Service Improper Initialization Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2023-27324HIGHParallels Desktop Updater Improper Initialization Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2023-27325HIGHParallels Desktop Updater Improper Initialization Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2022-34889HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (51537). An attacker EPSS 0.4%CVE-2022-34902HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacEPSS 0.3%CVE-2022-34901HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacEPSS 0.3%CVE-2021-34987HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker EPSS 0.3%CVE-2022-34890HIGHThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). AEPSS 0.3%CVE-2023-27328HIGHParallels Desktop Toolgate XML Injection Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2024-6240HIGHImproper privilege management vulnerability in Parallels DesktopEPSS 0.3%CVE-2021-31422HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An attacker muEPSS 0.3%CVE-2022-34891HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. AnEPSS 0.3%CVE-2024-6153HIGHParallels Desktop Updater Protection Mechanism Failure Software Downgrade VulnerabilityEPSS 0.3%