Searching
..

Click anywhere to stop

KLA48969
Multiple vulnerabilities in Oracle VirtualBox

Updated: 01/25/2024
Detect date
?
04/18/2023
Severity
?
High
Description

Multiple vulnerabilities were found in Oracle VirtualBox. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Code execution vulnerability in Core can be exploited to execute arbitrary code and obtain sensitive information.
  2. Code execution vulnerability in Core can be exploited to execute arbitrary code and obtain sensitive information and cause denial of service.
  3. Information disclosure vulnerability in Core can be exploited to obtain sensitive information.
  4. Information disclosure vulnerability in curl can be exploited to obtain sensitive information.
Affected products

Oracle VirtualBox earlier than 6.1.44
Oracle VirtualBox 7.0.x earlier than 7.0.8

Solution

Update to the latest version
Download VirtualBox

Original advisories

Oracle Critical Patch Update Advisory – April 2023

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]
Related products
Oracle VirtualBox
CVE-IDS
?
CVE-2022-429167.5Critical
CVE-2023-220014.6Warning
CVE-2023-219877.8Critical
CVE-2023-219993.6Warning
CVE-2023-220026.0High
CVE-2023-219883.8Warning
CVE-2023-220004.6Warning
CVE-2023-219908.2Critical
CVE-2023-219896.0High
CVE-2023-219984.6Warning
CVE-2023-219913.2Warning
Find out the statistics of the vulnerabilities spreading in your region