CVE-2025-31359: Parallels Desktop
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.
Affected products
- Parallels Parallels Desktop: version 20.2.2_(55879) only
Published 2025-06-03. Last modified 2026-06-17.