CVE-2021-34856 is a privilege escalation vulnerability affecting Parallels Desktop 16.1.3 (49160), specifically within the virtio-gpu virtual device. This flaw, stemming from improper validation of user-supplied data, leads to memory corruption. With a CVSS score of 8.8 (High), a local attacker with high-privileged code execution on the guest system can exploit this to escalate privileges and execute arbitrary code on the hypervisor. There is currently no public exploit intelligence, Metasploit modules, or significant community discussion, indicating a low likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.1.3CPE matchmatch criteria | cpe:2.3:a:parallels:parallels_desktop:16.1.3:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.