CVE-2017-3575
Oracle VM VirtualBox - 'virtio-net' Guest-to-Host Out-of-Bounds Write
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H).
Vulnerabilidad en el componente Oracle VM VirtualBox de Oracle Virtualization (subcomponente: Core). Versiones compatibles que son afectadas son anteriores a 5.0.38 y anteriores a 5.1.20. Vulnerabilidad fácilmente explotable permite al atacante de alto privilegio con el inicio de sesión a la infraestructura donde Oracle VM VirtualBox se ejecuta para comprometer a Oracle VM VirtualBox. Aunque la vulnerabilidad está en Oracle VirtualBox, los ataques pueden afectar significativamente a otros productos. Los ataques exitosos de esta vulnerabilidad pueden resultar en la creación, eliminación o modificación no autorizada de acceso a datos críticos o todos los datos accesibles de Oracle VirtualBox y la capacidad no autorizada para provocar un bloqueo o caída de frecuencia repetible (complete DOS) de Oracle VM VirtualBox. CVSS 3.0 Base Score 7.9 (Integridad e Impactos de disponibilidad). Vector CVSS: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H).
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2016-12-06 CVE Reserved
- 2017-04-19 CVE Published
- 2023-03-08 EPSS Updated
- 2024-10-07 CVE Updated
- 2024-10-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97755 | Third Party Advisory | |
http://www.securitytracker.com/id/1038288 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/41906 | 2024-10-07 |
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html | 2019-10-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Vm Virtualbox Search vendor "Oracle" for product "Vm Virtualbox" | >= 5.0.0 < 5.0.38 Search vendor "Oracle" for product "Vm Virtualbox" and version " >= 5.0.0 < 5.0.38" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Vm Virtualbox Search vendor "Oracle" for product "Vm Virtualbox" | >= 5.1.0 < 5.1.20 Search vendor "Oracle" for product "Vm Virtualbox" and version " >= 5.1.0 < 5.1.20" | - |
Affected
|