CVE-2024-6240: Parallels Desktop

Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.

Affected products

  • Parallels Parallels Desktop: before 19.3.0 (fixed in 19.3.0)

Published 2024-06-21. Last modified 2026-06-17.