CVE-2025-30074
Published: 16 March 2025
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2025-30074 is a privilege escalation vulnerability affecting Alludo Parallels Desktop versions before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms. The flaw, tied to CWE-863 (Incorrect Authorization), occurs in the VM creation routine and enables escalation to root privileges. It carries a CVSS v3.1 base score of 7.8 (AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H) and was published on 2025-03-16.
A local attacker with low privileges on the host macOS system can exploit this vulnerability. Exploitation requires high attack complexity but no user interaction. Success grants high-impact access to confidentiality, integrity, and availability, with a changed scope, allowing the attacker to achieve full root privileges on the Intel-based macOS host.
The Parallels knowledge base advisory at https://kb.parallels.com/en/130944 addresses mitigation by recommending updates to Parallels Desktop 19.4.2 or 20.2.2, which resolve the VM creation routine issue.
Details
- CWE(s)
MITRE ATT&CK Enterprise Techniques
Why these techniques?
The CVE describes a local privilege escalation vulnerability (CWE-863) in Parallels Desktop VM creation routine, directly enabling T1068 Exploitation for Privilege Escalation to gain root on the macOS host.