CVE-2025-54189
Adobe Substance 3D Painter vulnerability analysis and mitigation

Overview

A privilege escalation vulnerability (CVE-2024-54189) was discovered in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). The vulnerability was disclosed on June 3, 2025, and was discovered by KPC of Cisco Talos. The vulnerability affects the Parallels Desktop application, which is a desktop virtualization software that allows users to run macOS, Windows, or Linux virtual machines on Mac systems (Talos Report).

Technical details

The vulnerability exists in the prldispservice, which runs with root privileges and manages communication between macOS, Parallels Desktop, and virtual machines. When a snapshot of a virtual machine is taken, the service writes details about the snapshot to a snapshot.xml file in the VM directory owned by a normal user. The vulnerability has been assigned a CVSS v3.1 score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. It is classified under CWE-62 (UNIX Hard Link) (Talos Report).

Impact

The vulnerability allows a low-privilege user to potentially overwrite arbitrary files and escalate their privileges to those of a root user. By exploiting this vulnerability, an attacker can write to arbitrary files owned by root, potentially performing privileged actions such as modifying system files or gaining unauthorized administrative access (Talos Report).

Mitigation and workarounds

The vulnerability was patched by the vendor on April 17, 2025. Users should update to a version newer than Parallels Desktop for Mac version 20.1.1 (build 55740) to mitigate this vulnerability (Talos Report).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management