CVE-2007-2455
Last modified
CVE-2007-2455 is a vulnerability of currently unknown severity. Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrated by INT 0xAA; (2) an IRET instruction when an invalid address is at the top of the stack; (3) a malformed MOVNTI instruction, as demonstrated by using a register as a destination; or a write operation to (4) SEGR6 or (5) SEGR7.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrated by INT 0xAA; (2) an IRET instruction when an invalid address is at the top of the stack; (3) a malformed MOVNTI instruction, as demonstrated by using a register as a destination; or a write operation to (4) SEGR6 or (5) SEGR7.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Parallels | Parallels Desktop | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2455?
How severe is CVE-2007-2455?
How do I fix CVE-2007-2455?
Are you affected by CVE-2007-2455?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
