# CVE-2020-17392

## Summary

- **CVE ID:** CVE-2020-17392
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-822
- **Published:** Aug 25, 2020
- **Last Modified:** Mar 14, 2026

## Description

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handler for HOST_IOCTL_SET_KERNEL_SYMBOLS in the prl_hypervisor kext. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the kernel. Was ZDI-CAN-10519.

## Affected Products

- Parallels — Desktop (15.1.3-47255)

## References

- [CNA](https://kb.parallels.com/en/125013)
- [CNA](https://www.zerodayinitiative.com/advisories/ZDI-20-1010/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 27.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._