
Privilege Escalation via Parallels Appliance Extract Argument Injection
Elastic Detection Rules
View SourceSummary
Detects a local privilege escalation attempt on macOS by monitoring Parallels Desktop's root dispatcher (prl_disp_service) spawning tar/bsdtar with more arguments than the fixed extract command uses. The expected command is tar -xf <archive> -C <dir> (five tokens); any additional arguments imply an attacker-controlled folder name injecting extra tar flags. On affected macOS builds, such flags can cause tar to read/write attacker-chosen paths or execute an external program as root, enabling privilege escalation (CVE-2026-90894, Parallels Desktop < 27.0.0). The rule narrows to macOS endpoints where the parent process is prl_disp_service and the child process is tar or bsdtar with argument count greater than five, and validates the presence of -xf in the arguments. It then concatenates the arguments for readability and surfaces relevant identifiers for investigation. Remediation guidance includes isolating the host, terminating the injected process and any root children, upgrading Parallels Desktop to 27.0.0 or later, and restricting local logins on 26.x builds to limit access to the dispatcher socket until patched.
Categories
- Endpoint
- macOS
Data Sources
- Process
ATT&CK Techniques
- T1068
- T1202
Created: 2026-09-17