Executive brief
A vulnerability in Oracle VM VirtualBox's Shared Folder feature allows a high-privileged user on a guest system to compromise the virtualization software. This can lead to the unauthorized modification or deletion of critical data and can be used to crash the virtual machine environment entirely. Such an exploit could disrupt business operations and impact the integrity of data stored within the virtualized infrastructure.
Technical details
A vulnerability exists in the Shared Folder subcomponent of Oracle VM VirtualBox (versions prior to 5.0.32 and 5.1.14). The flaw is categorized as 'easily exploitable' and requires a high-privileged attacker with local logon access to the infrastructure where VirtualBox executes. Successful exploitation allows an attacker to perform unauthorized creation, deletion, or modification of critical data or all accessible data within VirtualBox. Additionally, the attacker can cause a persistent hang or repeatable crash, resulting in a complete denial of service. The vulnerability is notable for its 'Scope' impact (S:C), meaning an exploit in VirtualBox can impact the underlying host or other products.
Affected products
- Oracle VM VirtualBox prior to 5.0.32, prior to 5.1.14
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle Critical Patch Update (CPU) released