CVE-2024-6240: Parallels Desktop
Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.
Affected products
- Parallels Parallels Desktop: before 19.3.0 (fixed in 19.3.0)
Published 2024-06-21. Last modified 2026-06-17.