Oracle Secure Global Desktop Vulnerability in Oracle Virtualization
CVE-2021-2446

9.6CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 July 2021

Summary

A vulnerability in Oracle Secure Global Desktop, part of Oracle's Virtualization suite, allows an unauthenticated attacker with network access to exploit the system. This issue requires user interaction for successful exploitation, which can lead to a complete takeover of the desktop environment. The ramifications extend beyond the Secure Global Desktop, potentially affecting other systems within the network.

Affected Version(s)

Secure Global Desktop 5.6

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.