security1 publisher
JFrog says a stock Parallels Desktop install hands any local user a root shell
JFrog found that an unprivileged account on a Mac running Parallels Desktop 26.4.0 can reach the root dispatcher over a world-writable socket and run code as uid 0 through argument injection in the appliance installer.
Publishers:jfrog.com
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence58