PT-2024-6968 · Oracle+3 · Virtualbox+3

Yingmuo

·

Published

2024-10-15

·

Updated

2025-10-10

·

CVE-2024-21259

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions prior to 7.0.22 Oracle VM VirtualBox versions prior to 7.1.2
Description A difficult to exploit vulnerability in Oracle VM VirtualBox allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. The vulnerability is related to errors in authorization due to a buffer overflow in memory. Successful attacks can result in takeover of Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.
Recommendations For Oracle VM VirtualBox versions prior to 7.0.22, update to version 7.0.22 or later. For Oracle VM VirtualBox versions prior to 7.1.2, update to version 7.1.2 or later. As a temporary workaround, consider restricting access to the Core component of Oracle VM VirtualBox to minimize the risk of exploitation.

Fix

Incorrect Authorization

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17317
ALT-PU-2025-12585
ALT-PU-2025-12587
ALT-PU-2025-12588
ALT-PU-2025-12589
ALT-PU-2025-12590
BDU:2024-08217
CVE-2024-21259
MGASA-2025-0002
OPENSUSE-SU-2024:0364-1
OPENSUSE-SU-2024_0364-1
ZDI-24-1413

Affected Products

Alt Linux
Virtualbox
Red Os
Suse