PT-2024-3304 · Oracle+1 · Virtualbox+1

Dungdm

·

Published

2024-03-28

·

Updated

2025-05-01

·

CVE-2024-21113

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions prior to 7.0.16
Description The issue is related to an error in the initialization of variables in the Core component of Oracle VM VirtualBox. This easily exploitable vulnerability allows a low-privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks can result in the takeover of Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.
Recommendations For versions prior to 7.0.16, update to version 7.0.16 or later to resolve the issue. At the moment, there is no information about other versions that contain a fix for this vulnerability.

Fix

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-03538
CVE-2024-21113
MGASA-2024-0232
ZDI-24-415
ZDI-25-257

Affected Products

Virtualbox
Red Os