Description
Multiple serious vulnerabilities have been found in Oracle VM VirtualBox. Malicious users can exploit these vulnerabilities to to cause a denial of service, read and write accesible data and possibly to obtain sensitive information.
Below is a complete list of vulnerabilities:
- Multiple unspecified vulnerabilities in subcomponent Core of Oracle Virtualization component can be exploited remotely possibly to obtain sensitive information;
- An unspecified vulnerability in subcomponent Core of Oracle Virtualization component can be exploited remotely to cause a denial of service (it can be either hang or frequently repeatable crash), write to some of Oracle VM VirtualBox accessible data;
- An unspecified vulnerability in subcomponent Core of Oracle Virtualization component can be exploited remotely to cause a partial denial of service, read a subset of Oracle VM VirtualBox accessible data;
- Multiple unspecified vulnerabilities in subcomponent Core of Oracle Virtualization component can be exploited remotely to cause a denial of service (it can be either hang or frequently repeatable crash), write to some of Oracle VM VirtualBox accessible data and read a subset of Oracle VM VirtualBox accessible data;
- An unspecified vulnerability in subcomponent Core of Oracle Virtualization component can be exploited remotely to cause a denial of service (it can be either hang or frequently repeatable crash), write to some of Oracle VM VirtualBox accessible data;
- An unspecified vulnerability in subcomponent Core of Oracle Virtualization component can be exploited remotely to cause a partial denial of service, write to some of Oracle VM VirtualBox accessible data;
Technical details
Vulnerabilities (1)-(3) can be exploited by a low privileged user with logon to the infrastructure where OracleVM VirtualBox is executed.
Vulnerabilities (4)-(6) can be exploited by a high privileged user with logon to the infrastructure where OracleVM VirtualBox is executed.
NB: These vulnerabilities do not have any public CVSS rating so rating can be changed by the time.
NB: At this moment Oracle has just reserved CVE numbers for these vulnerabilities. Information can be changed soon.
Original advisories
Exploitation
Public exploits exist for this vulnerability.
Related products
CVE list
- CVE-2017-10204 critical
- CVE-2017-10129 critical
- CVE-2017-10210 high
- CVE-2017-10233 high
- CVE-2017-10236 high
- CVE-2017-10237 high
- CVE-2017-10238 high
- CVE-2017-10239 high
- CVE-2017-10240 high
- CVE-2017-10241 high
- CVE-2017-10242 high
- CVE-2017-10235 high
- CVE-2017-10209 high
- CVE-2017-10187 warning
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com