CVE-2024-6240
Last modified
CVE-2024-6240 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Parallels | Parallels Desktop | < 19.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-6240?
How severe is CVE-2024-6240?
How do I fix CVE-2024-6240?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6233Check Point ZoneAlarm Extreme Security Link Following Local …7.8
- CVE-2024-6235Sensitive information disclosure in NetScaler Console8.8
- CVE-2024-6236Denial of Service in NetScaler Console (formerly NetScaler…7.5
- CVE-2024-6237A flaw was found in the 389 Directory Server. This flaw allo…6.5
- CVE-2024-6238pgAdmin <= 8.8 has an installation Directory permission issu…5.3
- CVE-2024-6239A flaw was found in the Poppler's Pdfinfo utility. This issu…7.5
- CVE-2024-6241A vulnerability was found in Pear Admin Boot up to 2.0.2 and…9.8
- CVE-2024-6242A vulnerability exists in Rockwell Automation affected produ…7.3
- CVE-2024-6243The HTML Forms WordPress plugin before 1.3.33 does not sani…4.8
- CVE-2024-6244The PZ Frontend Manager WordPress plugin before 1.0.6 does n…8.8
- CVE-2024-6245Use of Default Credentials vulnerability in Maruti Suzuki Sm…7.4
- CVE-2024-6246Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow …8.8
Are you affected by CVE-2024-6240?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
