
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-34867 is a privilege escalation vulnerability affecting Parallels Desktop version 16.1.3-49160. The vulnerability was discovered in the Toolgate component and was disclosed on September 8, 2021. The issue stems from improper validation of user-supplied data, which can result in an uncontrolled memory allocation (Zero Day Initiative).
The vulnerability exists within the Toolgate component of Parallels Desktop. The specific flaw results from the lack of proper validation of user-supplied data, which can lead to an uncontrolled memory allocation. The vulnerability has been assigned a CVSS v3.1 base score of 8.2 HIGH (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) by NIST NVD, while Zero Day Initiative assigned it a CVSS score of 7.5 HIGH (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H) (NVD, Zero Day Initiative).
An attacker who successfully exploits this vulnerability can leverage it to escalate privileges and execute arbitrary code in the context of the hypervisor. The attacker must first obtain the ability to execute high-privileged code on the target guest system to exploit this vulnerability (Zero Day Initiative).
Parallels has issued an update to address this vulnerability. Users are recommended to update to the patched version of Parallels Desktop (Parallels KB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."