Exploitability in Oracle VM VirtualBox by Oracle
CVE-2017-3558

8.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

An exploit in Oracle VM VirtualBox allows unauthenticated attackers to access the infrastructure where it runs, potentially compromising sensitive data and system stability. This vulnerability enables attackers to cause denial of service by hanging or crashing Oracle VM VirtualBox. Moreover, it grants unauthorized access to modify, delete, or read available data, exposing systems relying on this virtualization technology to various risks. It is crucial for users of vulnerable versions to apply patches to secure their environments from potential attacks.

Affected Version(s)

Oracle VM VirtualBox < 5.0.38

Oracle VM VirtualBox < 5.1.20

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.