Executive brief
Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer, contains a security vulnerability in its graphical user interface. An attacker could trick a user into interacting with a malicious link or website to gain unauthorized access to data or cause the application to crash. This could lead to the theft of sensitive information or a disruption of work on the affected virtual machines.
Technical details
A vulnerability exists in the GUI subcomponent of Oracle VM VirtualBox (versions prior to 5.0.32 and 5.1.14). The flaw is categorized under CWE-254 (Security Features) and is exploitable by an unauthenticated attacker via the network using HTTP. Exploitation requires user interaction from someone other than the attacker, suggesting a cross-site or UI-based attack vector. If successful, the attacker can read, update, or delete a subset of accessible data and cause a partial denial of service. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle VM VirtualBox Prior to 5.0.32, prior to 5.1.14
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle January 2017 Critical Patch Update released