CVE-2025-31359

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
03/06/2025
Last modified:
02/07/2025

Description

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:parallels:parallels_desktop:20.2.2_\(55879\):*:*:*:*:macos:*:*