漏洞详情: CVE-2024-6154

漏洞标题
Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
来源:NVD
Parallels Desktop 安全漏洞
来源:CNNVD
漏洞描述
Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the current user on the host system. Was ZDI-CAN-20450.
来源:NVD
Corel Parallels Desktop是加拿大科亿尔数码科技(Corel)公司的一套适用于macOS平台的虚拟机软件。 Parallels Desktop存在安全漏洞,该漏洞源于在将用户提供的数据复制到固定长度的基于堆的缓冲区之前缺乏对数据长度的正确验证。
来源:CNNVD
NVD 暂无描述信息
来源:神龙机器人
漏洞评分(CVSS)
NVD 暂无评分
来源:NVD
漏洞类别
堆缓冲区溢出
来源:NVD
其他
来源:CNNVD
相关链接