{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-31359","assignerOrgId":"b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b","state":"PUBLISHED","assignerShortName":"talos","dateReserved":"2025-03-28T15:54:45.505Z","datePublished":"2025-06-03T09:43:25.931Z","dateUpdated":"2025-06-03T13:27:26.786Z"},"containers":{"cna":{"affected":[{"vendor":"Parallels","product":"Parallels Desktop for Mac","versions":[{"version":"20.2.2 (55879)","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","type":"CWE","cweId":"CWE-22"}]}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}],"providerMetadata":{"orgId":"b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b","shortName":"talos","dateUpdated":"2025-06-03T09:43:25.931Z"},"references":[{"url":"https://talosintelligence.com/vulnerability_reports/TALOS-2025-2160","name":"https://talosintelligence.com/vulnerability_reports/TALOS-2025-2160"}],"credits":[{"lang":"en","value":"Discovered by KPC of Cisco Talos."}]},"adp":[{"title":"CVE Program Container","references":[{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2160"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-06-03T11:03:08.458Z"}},{"references":[{"url":"https://talosintelligence.com/vulnerability_reports/TALOS-2025-2160","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-06-03T13:27:22.807674Z","id":"CVE-2025-31359","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-06-03T13:27:26.786Z"}}]}}