Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2017-3561

8.8HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

A vulnerability exists in Oracle VM VirtualBox that allows an authenticated low-privileged attacker to gain control over the virtualization platform. This flaw affects supported versions prior to 5.0.38 and 5.1.20. By leveraging this vulnerability, an attacker who has access to the infrastructure can successfully exploit weaknesses in the Oracle VM VirtualBox component, leading to potential takeover of the system. Such exploits can impact not only the virtual machine but also any additional products operating within the environment, thus emphasizing the need for immediate patching.

Affected Version(s)

Oracle VM VirtualBox < 5.0.38

Oracle VM VirtualBox < 5.1.20

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.