脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
N/A
脆弱性説明
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of root. Was ZDI-CAN-8685.
CVSS情報
N/A
脆弱性タイプ
在命令中使用的特殊元素转义处理不恰当(命令注入)
脆弱性タイトル
Corel Parallels Desktop 命令注入漏洞
脆弱性説明
Corel Parallels Desktop是加拿大Corel公司的一套适用于macOS平台的虚拟机软件。 Corel Parallels Desktop 14.1.3 (45485)版本中存在命令注入漏洞,该漏洞源于程序没有正确验证用户提交的字符串就直接进行系统调用。本地攻击者可利用该漏洞提升权限并执行代码。
CVSS情報
N/A
脆弱性タイプ
N/A