Parallels Desktop Flaw Exposes Mac Users to Root Access

A vulnerability in Parallels Desktop for Mac, discovered by JFrog, allows a non-admin user to gain root access, bypassing typical security controls.

Bottom line: Parallels Desktop for Mac users need to patch their systems immediately to prevent unauthorized access.

What's happening: A vulnerability, identified as CVE-2023-32697, exploits a buffer overflow in the Wine implementation, allowing a local non-admin user to run code as root on Intel Macs with macOS 12.6 and later, but not on Intel Macs with macOS 11.6 and earlier.

What to do: Security teams should deploy the Parallels Desktop patch to all affected systems, and users should avoid running untrusted code until the vulnerability is fully mitigated.

Source: The Hacker News