Oracle VM VirtualBox Vulnerability Allows Low Privileged Attackers to Compromise Virtual Machine
CVE-2024-21116

7.8HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

A vulnerability exists within the Oracle VM VirtualBox product line that could allow a low privileged attacker with access to the infrastructure where Oracle VM VirtualBox runs to compromise the application. Specifically, this issue is present in versions prior to 7.0.16 and is applicable only to Linux hosts. Exploitation of this vulnerability can lead to complete takeover of the Oracle VM VirtualBox environment, impacting confidentiality, integrity, and availability. Organizations utilizing Oracle VM VirtualBox must prioritize updating to the latest version and implement robust security measures to mitigate associated risks.

Affected Version(s)

VM VirtualBox * < 7.0.16

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre Database
.