PT-2024-4909 · Oracle+1 · Virtualbox+1

Coldeye

·

Published

2024-04-16

·

Updated

2024-12-05

·

CVE-2024-21112

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Oracle VM VirtualBox versions prior to 7.0.16
Description: The issue is related to an easily exploitable vulnerability in the Oracle VM VirtualBox product, specifically in the Core component. This vulnerability allows a low-privileged attacker with logon access to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks can result in the takeover of Oracle VM VirtualBox. The vulnerability may also significantly impact additional products due to a scope change.
Recommendations: For versions prior to 7.0.16, update to version 7.0.16 or later to resolve the issue. At the moment, there is no information about additional mitigation measures.

Fix

Improper Access Control

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-05433
CVE-2024-21112
MGASA-2024-0232
ZDI-24-414

Affected Products

Virtualbox
Red Os