Cyber Posture

CVE-2025-30074

High

Published: 16 March 2025

Published
16 March 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0005 14.5th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.

Security Summary

CVE-2025-30074 is a privilege escalation vulnerability affecting Alludo Parallels Desktop versions before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms. The flaw, tied to CWE-863 (Incorrect Authorization), occurs in the VM creation routine and enables escalation to root privileges. It carries a CVSS v3.1 base score of 7.8 (AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H) and was published on 2025-03-16.

A local attacker with low privileges on the host macOS system can exploit this vulnerability. Exploitation requires high attack complexity but no user interaction. Success grants high-impact access to confidentiality, integrity, and availability, with a changed scope, allowing the attacker to achieve full root privileges on the Intel-based macOS host.

The Parallels knowledge base advisory at https://kb.parallels.com/en/130944 addresses mitigation by recommending updates to Parallels Desktop 19.4.2 or 20.2.2, which resolve the VM creation routine issue.

Details

CWE(s)
CWE-863

MITRE ATT&CK Enterprise Techniques

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

The CVE describes a local privilege escalation vulnerability (CWE-863) in Parallels Desktop VM creation routine, directly enabling T1068 Exploitation for Privilege Escalation to gain root on the macOS host.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References