Vulnerabilities (CVE)

Filtered by CWE-62
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-32232 1 Aisarlabs 1 Zeptoclaw 2026-03-19 N/A 9.8 CRITICAL
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.
CVE-2024-36486 1 Parallels 1 Parallels Desktop 2025-07-02 N/A 7.8 HIGH
A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is restored, the prl_vmarchiver tool decompresses the file and writes the content back to its original location using root privileges. An attacker can exploit this process by using a hard link to write to an arbitrary file, potentially resulting in privilege escalation.
CVE-2024-54189 1 Parallels 1 Parallels Desktop 2025-07-02 N/A 7.8 HIGH
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard link, an attacker can write to an arbitrary file, potentially leading to privilege escalation.