KLA48969
Multiple vulnerabilities in Oracle VirtualBox

Updated: 04/19/2023
Detect date
?
04/18/2023
Severity
?
High
Description

Multiple vulnerabilities were found in Oracle VirtualBox. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Code execution vulnerability in Core can be exploited to execute arbitrary code and obtain sensitive information.
  2. Code execution vulnerability in Core can be exploited to execute arbitrary code and obtain sensitive information and cause denial of service.
  3. Information disclosure vulnerability in Core can be exploited to obtain sensitive information.
  4. Information disclosure vulnerability in curl can be exploited to obtain sensitive information.
Exploitation

The following public exploits exists for this vulnerability:

https://github.com/Live-Hack-CVE/CVE-2022-42916

Affected products

Oracle VirtualBox earlier than 6.1.44
Oracle VirtualBox 7.0.x earlier than 7.0.8

Solution

Update to the latest version
Download VirtualBox

Original advisories

Oracle Critical Patch Update Advisory – April 2023

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]
Related products
Oracle VirtualBox
CVE-IDS
?
CVE-2022-429165.0Critical
CVE-2023-220015.0Critical
CVE-2023-219875.0Critical
CVE-2023-219995.0Critical
CVE-2023-220025.0Critical
CVE-2023-219885.0Critical
CVE-2023-220005.0Critical
CVE-2023-219905.0Critical
CVE-2023-219895.0Critical
CVE-2023-219985.0Critical
CVE-2023-219915.0Critical
Find out the statistics of the vulnerabilities spreading in your region