PT-2026-3732 · Oracle+1 · Virtualbox+1

Phudq

·

Publicado

2026-01-01

·

Atualizado

2026-03-19

·

CVE-2026-21985

CVSS v3.1

6.0

Média

VetorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions 7.1.14 and 7.2.4
Description An easily exploitable issue exists in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). A high-privileged attacker with access to the infrastructure where Oracle VM VirtualBox runs can compromise the software. Successful exploitation may lead to unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. Attacks may significantly impact additional products.
Recommendations Update Oracle VM VirtualBox to a newer version that addresses this issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00841
CVE-2026-21985
ZDI-26-100

Produtos afetados

Virtualbox
Red Os