what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Parallels Tools 9.0 Privilege Escalation

Parallels Tools 9.0 Privilege Escalation
Posted Jul 28, 2014
Authored by Anastasios Monachos

Parallels Tools version 9.0 for Windows suffers from an unquoted search path local privilege escalation vulnerability.

tags | advisory, local
systems | windows
SHA-256 | 4ac561e0a8ae43976d960ffd7ca304c4850b8d9c8ae4062502ad7e6f64ca3b20

Parallels Tools 9.0 Privilege Escalation

Change Mirror Download
===============================================================================
Parallels Tools - Unquoted Search Path Local Privilege Escalation Vulnerability ===============================================================================

Affected Software : Parallels Tools 9.0 for Windows (shipped with Parallels Desktop 9 and probably other)
Local/Remote : Local
Severity : Medium
Discovered by : Anastasios Monachos (secuid0) - [anastasiosm (at) gmail (dot) com]

[Summary]
Parallels Tools are a suite of special utilities that help you use your virtual machines in the most comfortable and efficient way. With Parallels Tools, amongst other things you can synchronise your clipboard between the guest and host OS, you can share the primary OS folders to access them from the guest OS etc. For a full description of the Parallels Tools functionalities please see http://download.parallels.com/desktop/v4/docs/en/Parallels_Desktop_Users_Guide/22272.htm It was observed that Parallels Tools suffer by a flaw that may allow an attacker to gain access to unauthorized privileges.

[Vulnerability Details]
Two unquoted search path issues discovered, one impacting the Parallels Tools Service (prl_tools_service.exe) and another one impacting the Parallels Coherence Service (coherence.exe) for Windows, deployed as part of Parallels Tools. The vulnerability could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user’s code would execute with the elevated privileges of the application, typically SYSTEM privileges.

[Timeline]
16/02/2014 - Advisory created, shared with Parallels
17/02/2014 - Parallels requested more information
17/02/2014 - Conf call with representative from First line Technical Support
18/02/2014 - Parallels Second line Technical Support requested more information
19/02/2014 - Replied with extensive details of the vulnerability
20/02/2014 - Video demo; Parallels Support will share the information to their Development Team
08/07/2014 - Requested status update on existing ticket (no response)
27/07/2014 - Opened a new Ticket with Parallels Support requesting update
28/07/2014 - Parallels support team responded, Parallels does not have a guaranteed ETA for the fix
28/07/2014 - Advisory published
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close