KLA11521
Multiple vulnerabilities in Oracle VirtualBox
Updated: 07/19/2019
Detect date
?
07/16/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Oracle VirtualBox. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Multiple vulnerabilities in Core component of Oracle VM VirtualBox can be exploited locally to unspecified impact;
  2. Vulnerability in Core (OpenSSL) component of Oracle VM VirtualBox can be exploited remotely to obtain sensitive information and bypass security restrictions.

Technical details

The vulnerability affects Windows platforms only.

Affected products

Oracle VirtualBox prior to 5.2.32, prior to 6.0.10

Solution

Update to the latest version

Original advisories

Oracle Critical Patch Update Advisory – July 2019

Impacts
?
OSI 
[?]

SB 
[?]
Related products
Oracle VirtualBox
CVE-IDS
?
CVE-2019-28590.0Unknown
CVE-2019-28670.0Unknown
CVE-2019-28660.0Unknown
CVE-2019-28640.0Unknown
CVE-2019-28650.0Unknown
CVE-2019-15430.0Unknown
CVE-2019-28630.0Unknown
CVE-2019-28480.0Unknown
CVE-2019-28770.0Unknown
CVE-2019-28730.0Unknown
CVE-2019-28740.0Unknown
CVE-2019-28750.0Unknown
CVE-2019-28760.0Unknown
CVE-2019-28500.0Unknown