PT-2016-4344 · Oracle+1 · Virtualbox+1

Stefan Kanthak

·

Published

2016-01-21

·

Updated

2018-10-09

·

CVE-2016-0602

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions prior to 5.0.14
Description The issue affects confidentiality, integrity, and availability. It is related to unknown vectors and the Windows Installer. There are claims that this could be an untrusted search path issue, potentially allowing local users to gain privileges via a Trojan horse dll in the application directory.
Recommendations For versions prior to 5.0.14, update to version 5.0.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the application directory to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2016-1230
ALT-PU-2016-1231
ALT-PU-2016-1232
ALT-PU-2016-1256
ALT-PU-2016-1263
CVE-2016-0602

Affected Products

Alt Linux
Virtualbox