Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper privilege management vulnerability in Parallels Desktop
Vulnerability Description
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
特权管理不恰当
Vulnerability Title
Corel Parallels Desktop 安全漏洞
Vulnerability Description
Corel Parallels Desktop是加拿大科亿尔数码科技(Corel)公司的一套适用于macOS平台的虚拟机软件。 Parallels Desktop 19.3.0之前的版本存在安全漏洞,该漏洞源于存在权限管理不当漏洞,从导致攻击者可以在脚本中添加恶意代码并在应用程序启动时执行。
CVSS Information
N/A
Vulnerability Type
N/A