Vulnerabilidades en Parallels

80 resultados
Análisis Vexday

Com 80 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco imediato do Parallels situa-se abaixo da média geral do catálogo, sem registros de severidade crítica, PoCs públicas disponíveis ou novas vulnerabilidades nos últimos 90 dias. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que, embora não represente risco imediato elevado, costuma servir de base para cadeias de exploração mais complexas quando combinado com outras vulnerabilidades. A CVE de maior atenção no momento é CVE-2025-31359, com escore EPSS de 0,0168, indicando probabilidade de exploração ainda baixa no curto prazo. Equipes de segurança podem manter monitoramento de rotina, priorizando o controle de CVEs relacionadas a leituras de memória fora dos limites e acompanhando eventuais evoluções no EPSS de CVE-2025-31359.

CVE-2021-31427HIGHThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An EPSS 0.3%CVE-2024-54189HIGHA privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a EPSS 0.3%CVE-2024-36486HIGHA privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20EPSS 0.3%CVE-2021-27243HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An attacker muEPSS 0.3%CVE-2020-8968HIGHParallels Remote Application Server credentials management errorsEPSS 0.3%CVE-2021-27242HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An attacker muEPSS 0.3%CVE-2021-27244MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.0.1-48919. An EPSS 0.3%CVE-2021-34986HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker EPSS 0.3%CVE-2021-34857HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.3%CVE-2021-34856HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.3%CVE-2021-34855MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.1.3 (49160). AEPSS 0.3%CVE-2022-34892HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. AnEPSS 0.3%CVE-2024-6154HIGHParallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2021-34854HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.2%CVE-2024-52561HIGHA privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a EPSS 0.2%CVE-2022-34899HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacEPSS 0.2%CVE-2021-34864HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.2%CVE-2023-50228HIGHParallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2023-27323HIGHParallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-30074HIGHAlludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM crEPSS 0.1%