CVE-2023-50226

Source
https://cve.org/CVERecord?id=CVE-2023-50226
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50226.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-50226
Published
2024-05-03T03:16:11.160Z
Modified
2026-03-15T22:47:43.049460Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability.

The specific flaw exists within the Updater service. By creating a symbolic link, an attacker can abuse the service to move arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. . Was ZDI-CAN-21227.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "17.1.7_\\(51588\\)"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "18.0.0_\\(53049\\)"
            },
            {
                "fixed": "18.3.2_\\(53621\\)"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50226.json"