CVE-2023-27326 is a local privilege escalation vulnerability in the Toolgate component of Parallels Desktop. The vulnerability arises from improper validation of user-supplied paths before they are used in file operations, allowing directory traversal. A local attacker with the ability to execute code on the guest system can exploit this flaw to escalate privileges and execute arbitrary code as the current user on the host system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (POC) exploit for CVE-2023-27326, a local privilege escalation and VM escape vulnerability in Parallels Desktop for macOS (tested on version 18.0.0 (53049)). The vulnerability resides in the Toolgate component, which fails to properly validate user-supplied paths before performing file operations, allowing an attacker to write arbitrary files on the host system from within a VM. The main exploit logic is implemented in 'prl_exp.c', a Linux kernel module that interacts with the vulnerable PCI device (vendor 0x1ab8, device 0x4000) exposed by Parallels. The exploit crafts a request that writes a command to '../../../.zshrc' on the host, which, when executed, opens Calculator.app as a demonstration of code execution. The 'run.sh' script loads the kernel module and tails the kernel log for output. The repository is structured with standard build files (Makefile, .gitignore), documentation (README.md), and the exploit code. No network endpoints are involved; the attack vector is local, requiring the ability to load a kernel module within the VM. The exploit demonstrates the vulnerability but does not include a weaponized or highly automated payload.
This repository contains a working exploit for CVE-2023-27326, a local privilege escalation vulnerability in Parallels Desktop for macOS (tested on version 18.0.0 (53049)). The exploit targets the Toolgate component, which fails to properly validate user-supplied paths in file operations. The main exploit logic is implemented in 'prl_exp.c' as a Linux kernel module. When loaded, the module registers a PCI driver for the Parallels virtual device, and in its probe function, it triggers the exploit. The exploit crafts a malicious request to the Toolgate interface, attempting to execute the command 'open /System/Applications/Calculator.app' and write to '../../../.zshrc' on the host, demonstrating both code execution and file write capabilities. The 'run.sh' script automates loading the kernel module and monitoring kernel logs. The Makefile is used to build the kernel module. The repository is operational and demonstrates real-world exploitation of the vulnerability, requiring root access to load the kernel module. No network endpoints are present; the attack vector is local, leveraging guest-to-host escape via a vulnerable device interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.