A critical local privilege escalation vulnerability in Parallels Desktop for Mac has created a significant security gap: the official fix is only available for Apple Silicon Macs, leaving Intel-based users without a vendor patch. Disclosed by security firm JFrog, the flaw allows a standard user to escalate their privileges to root, granting complete administrative control over the machine.
The attack vector is limited to local exploitation, requiring an attacker to first execute malicious code on the target Mac as a normal user. It cannot be triggered remotely. Despite this precondition, the security impact is severe. As reported by The Hacker News, any local attacker could use this flaw to gain full system control.
The core issue lies in remediation. According to JFrog, the necessary fix has been incorporated into Parallels Desktop version 27. However, this version is designed exclusively for Macs with Apple Silicon processors. For the many users and organizations still running Intel-based Macs, no corresponding patch is available from the vendor, and their systems will remain vulnerable to this known, exploitable flaw.
This scenario highlights a challenging transition in the macOS ecosystem. As software vendors align their development with Apple's latest hardware architecture, support for legacy platforms can be discontinued. For IT teams managing mixed fleets of Mac hardware, this creates an immediate dilemma: a critical security flaw with an unattainable official fix on a significant portion of their devices.
Affected Intel Mac users must focus on risk mitigation. Security professionals recommend immediate steps:
- Audit and Inventory: Identify all Mac systems running Parallels Desktop on Intel processors to understand the scope of exposure.
- Assess Risk: Evaluate the criticality of data and operations conducted on these virtualized machines. Systems handling sensitive information present a higher risk.
- Implement Controls: Enforce stricter application controls to reduce the likelihood of the initial code execution required to trigger the flaw. This includes limiting software installation privileges and enhancing endpoint detection and response (EDR) monitoring.
- Network Isolation: Consider isolating highly sensitive Intel Macs from broader networks to contain potential breaches.
- Evaluate Alternatives: Assess whether switching to a different virtualization platform with supported versions for Intel Macs is a viable alternative for critical workloads.
This vulnerability underscores that a device's security posture can be compromised not just by unpatched operating systems, but by third-party applications reaching a vendor support dead end. For organizations, the immediate priority is assessing real-world risk on Intel Macs running Parallels and executing necessary compensating controls to protect systems in the absence of a vendor-provided solution.
Parallels Desktop for Mac 中存在一個嚴重的本地權限提升漏洞,造成了重大的安全缺口:官方修復僅適用於 Apple Silicon Mac,令使用 Intel 處理器 Mac 的用戶無法獲得供應商補丁。該漏洞由安全公司 JFrog 披露,容許普通用戶將權限提升至 root,從而獲得對電腦的完整管理員控制權。
攻擊向量僅限於本地利用,需要攻擊者先以普通用戶身份在目標 Mac 上執行惡意代碼。無法遠端觸發。儘管有此前提條件,其安全影響仍然嚴重。據 The Hacker News 報導,任何本地攻擊者均可利用此漏洞取得完整的系統控制權。
核心問題在於修補方案。根據 JFrog 的資料,必要的修復已納入 Parallels Desktop 第 27 版。然而,此版本專為搭載 Apple Silicon 處理器的 Mac 設計。對於眾多仍在使用 Intel Mac 的用戶和組織,供應商並無提供相應的補丁,其系統將持續容易受到此已知可利用漏洞的攻擊。
此情況突顯了 macOS 生態系統中一個具挑戰性的過渡期。隨著軟件供應商將開發與 Apple 最新的硬件架構對齊,對舊有平台的支持可能會被終止。對於管理混合 Mac 硬件設備組合的 IT 團隊而言,這帶來了直接的困境:一個嚴重的安全漏洞,官方修補方案卻無法適用於其相當一部分的設備。
受影響的 Intel Mac 用戶必須專注於風險緩解。安全專家建議即時採取以下步驟:
- 審計與盤點: 識別所有在 Intel 處理器上運行 Parallels Desktop 的 Mac 系統,以了解暴露的範圍。
- 風險評估: 評估這些虛擬化機器上處理的數據和運作的關鍵程度。處理敏感資訊的系統風險更高。
- 實施控制措施: 實施更嚴格的應用程式控制,以減少觸發此漏洞所需的初步代碼執行的可能性。這包括限制軟件安裝權限及加強端點偵測與回應(EDR)監控。
- 網絡隔離: 考慮將高度敏感的 Intel Mac 與更廣泛的網絡隔離,以遏制潛在的入侵。
- 評估替代方案: 評估轉用另一個為 Intel Mac 提供受支持版本的虛擬化平台,是否對關鍵工作負載而言是一個可行的替代方案。
此漏洞突顯了一個設備的安全態勢,不僅可能因未修補的操作系統而受損,也可能因第三方應用軟件達到供應商支持的死胡同而受損。對組織而言,當務之急是評估在運行 Parallels 的 Intel Mac 上的實際風險,並在缺乏供應商解決方案的情況下,執行必要的補償性控制措施以保護系統。
