PT-2007-2643 · Parallels · Parallels Desktop For Mac
Publicado
2007-03-02
·
Atualizado
2008-11-15
·
CVE-2007-1222
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Parallels Desktop for Mac versions prior to 20070216
Description
The issue allows local users of the guest operating system to write arbitrary files to the host filesystem and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory. This is due to the implementation of Drag and Drop, which shares the entire host filesystem as the .psf share.
Recommendations
For Parallels Desktop for Mac versions prior to 20070216, update to a version released after 20070216 to resolve the issue. As a temporary workaround, consider restricting access to the LaunchAgents directory to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Parallels Desktop For Mac