Parallels · Parallels Desktop · CVE-2021-34986
**Name of the Vulnerable Software and Affected Versions**
Parallels Desktop version 16.5.0
**Description**
This issue allows local attackers to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this issue. The specific flaw exists within the Parallels Service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this issue to escalate privileges and execute arbitrary code in the context of root.
**Recommendations**
For Parallels Desktop version 16.5.0, at the moment, there is no information about a newer version that contains a fix for this issue.