what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Parallels Tools 9.0 Privilege Escalation

Parallels Tools 9.0 Privilege Escalation
Posted Jul 28, 2014
Authored by Anastasios Monachos

Parallels Tools version 9.0 for Windows suffers from an unquoted search path local privilege escalation vulnerability.

tags | advisory, local
systems | windows
SHA-256 | 4ac561e0a8ae43976d960ffd7ca304c4850b8d9c8ae4062502ad7e6f64ca3b20

Parallels Tools 9.0 Privilege Escalation

Change Mirror Download
===============================================================================
Parallels Tools - Unquoted Search Path Local Privilege Escalation Vulnerability ===============================================================================

Affected Software : Parallels Tools 9.0 for Windows (shipped with Parallels Desktop 9 and probably other)
Local/Remote : Local
Severity : Medium
Discovered by : Anastasios Monachos (secuid0) - [anastasiosm (at) gmail (dot) com]

[Summary]
Parallels Tools are a suite of special utilities that help you use your virtual machines in the most comfortable and efficient way. With Parallels Tools, amongst other things you can synchronise your clipboard between the guest and host OS, you can share the primary OS folders to access them from the guest OS etc. For a full description of the Parallels Tools functionalities please see http://download.parallels.com/desktop/v4/docs/en/Parallels_Desktop_Users_Guide/22272.htm It was observed that Parallels Tools suffer by a flaw that may allow an attacker to gain access to unauthorized privileges.

[Vulnerability Details]
Two unquoted search path issues discovered, one impacting the Parallels Tools Service (prl_tools_service.exe) and another one impacting the Parallels Coherence Service (coherence.exe) for Windows, deployed as part of Parallels Tools. The vulnerability could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user’s code would execute with the elevated privileges of the application, typically SYSTEM privileges.

[Timeline]
16/02/2014 - Advisory created, shared with Parallels
17/02/2014 - Parallels requested more information
17/02/2014 - Conf call with representative from First line Technical Support
18/02/2014 - Parallels Second line Technical Support requested more information
19/02/2014 - Replied with extensive details of the vulnerability
20/02/2014 - Video demo; Parallels Support will share the information to their Development Team
08/07/2014 - Requested status update on existing ticket (no response)
27/07/2014 - Opened a new Ticket with Parallels Support requesting update
28/07/2014 - Parallels support team responded, Parallels does not have a guaranteed ETA for the fix
28/07/2014 - Advisory published
Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    0 Files
  • 21
    Mar 21st
    0 Files
  • 22
    Mar 22nd
    0 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close