vendor:
Parallels Desktop
by:
Mohammad Reza Espargham
8,8
CVSS
HIGH
Escape from Virtual Machine
20
CWE
Product Name: Parallels Desktop
Affected Version From: All Versions
Affected Version To: All Versions
Patch Exists: YES
Related CWE: None
CPE: parallels:desktop
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2020
Parallels Desktop – Virtual Machine Escape
There is a security issue in the shared folder implementation in Parallels Desktop. The exploit uses a DLL called PrlToolsShellExt.dll and prl_tg Driver. It uses a very simple exploit with powershell to write an OSX Executable file in temp, open the temp in explorer, select the Temp active window, find the r3z4.command file, right click, goto 'Open on Mac' in the menu and click Enter.
Mitigation:
Update to the latest version of Parallels Desktop.