Vulnerability in Oracle VM VirtualBox Affects Shared Folder Functionality
CVE-2017-3587

8.4HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

A significant vulnerability exists in Oracle VM VirtualBox that affects its shared folder functionality. Attackers with low privileges who can log on to the infrastructure where Oracle VM VirtualBox runs can exploit this flaw, potentially leading to unauthorized creation, deletion, or modification of critical data. Furthermore, the exploit can allow attackers to cause the application to hang or crash, resulting in a denial of service. The supported versions of Oracle VM VirtualBox prior to 5.0.38 and 5.1.20 are notably at risk, as successful exploitation could have far-reaching effects beyond the application itself.

Affected Version(s)

Oracle VM VirtualBox < 5.0.38

Oracle VM VirtualBox < 5.1.20

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.