7.8
CVSSv3

CVE-2025-0413

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 0.00043 | KEV: Not Included
Published: 05/02/2025 Updated: 05/02/2025

Vulnerability Summary

Local Privilege Escalation in Parallels Desktop via Technical Data Reporter Symbolic Link

A local privilege escalation vulnerability exists in Parallels Desktop through the Technical Data Reporter component. This issue allows a local attacker who can execute low-privileged code to escalate privileges on the target system. By creating a symbolic link, the attacker can manipulate file permissions and potentially execute arbitrary code with root-level access. The vulnerability was identified as ZDI-CAN-25014 and requires the attacker to already have some initial access to the system before exploitation can occur.

Vulnerable Product Search on Vulmon Subscribe to Product

parallels desktop