Junglewise Threat Intelligence

CVE-2016-5545: Oracle VM VirtualBox data manipulation in GUI

CVE-2016-5545 · Severity: medium · CVSS 6.3 · Published 2017-01-27

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer, contains a security vulnerability in its graphical user interface. An attacker could trick a user into interacting with a malicious link or website to gain unauthorized access to data or cause the application to crash. This could lead to the theft of sensitive information or a disruption of work on the affected virtual machines.

Technical details

A vulnerability exists in the GUI subcomponent of Oracle VM VirtualBox (versions prior to 5.0.32 and 5.1.14). The flaw is categorized under CWE-254 (Security Features) and is exploitable by an unauthenticated attacker via the network using HTTP. Exploitation requires user interaction from someone other than the attacker, suggesting a cross-site or UI-based attack vector. If successful, the attacker can read, update, or delete a subset of accessible data and cause a partial denial of service. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle VM VirtualBox Prior to 5.0.32, prior to 5.1.14

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update released

References

Related threats