CVE-2020-8876 is a local information disclosure vulnerability affecting Parallels Desktop 15.1.2-47123. The flaw stems from insufficient validation of user-supplied data within an IOCTL handler, leading to a read past the end of an allocated buffer. Rated as Medium severity (CVSS 5.5), exploitation requires an attacker to first gain low-privileged code execution on the target system. While it primarily allows information disclosure, it could be chained with other vulnerabilities to achieve arbitrary kernel-level code execution. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.1.3CPE matchmatch criteria | cpe:2.3:a:parallels:parallels_desktop:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.