CVE-2025-31359HIGH 8.8EPSS p73.3%

CVE-2025-31359CVE-2025-31359

Description

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS1.64% probability of exploitation · percentile 73.3% · 2026-06-19T12:03:05Z
Published2025-06-03
Last modified2025-07-02

Underlying weaknesses· 1

CWE-22

References

  1. https://talosintelligence.com/vulnerability_reports/TALOS-2025-2160
  2. https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2160
  3. https://talosintelligence.com/vulnerability_reports/TALOS-2025-2160

1

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-43243
CVE
CVE-2025-24233
CVE
CVE-2025-43194
CVE
CVE-2025-30457
CVE
CVE-2025-43257
CVE
CVE-2025-31244
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.