← Volver a CVEs
CVE-2025-31359
HIGH8.8
Descripcion
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.
Detalles CVE
Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado6/3/2025
Ultima modificacion7/2/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
parallels:parallels_desktop
Debilidades (CWE)
CWE-22
Referencias
https://talosintelligence.com/vulnerability_reports/TALOS-2025-2160(talos-cna@cisco.com)
https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2160(af854a3a-2127-422b-91ae-364da2661108)
https://talosintelligence.com/vulnerability_reports/TALOS-2025-2160(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.