Untrusted Pointer Dereference in Parallels Desktop - CVE-2020-17392
Published: August 19, 2020
Parallels Desktop
Parallels
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to untrusted pointer dereference error when handling HOST_IOCTL_SET_KERNEL_SYMBOLS in the prl_hypervisor kext. A local user to can run a specially crafted program to trigger pointer dereference and execute arbitrary code on the system in the context of the kernel.