Junglewise Threat Intelligence

CVE-2017-3316: Oracle VM VirtualBox privilege escalation in GUI update downloader

CVE-2017-3316 · Severity: high · CVSS 8.4 · Published 2017-01-27

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a popular virtualization tool used to run multiple operating systems on a single computer. A vulnerability in its update mechanism allows an attacker to take full control of the host computer if a user is tricked into downloading a malicious update. This could lead to the theft of sensitive data, system-wide service outages, or the installation of ransomware on the host machine.

Technical details

A privilege escalation vulnerability exists in the Oracle VM VirtualBox GUI subcomponent, specifically within the Extension Pack update downloader. The root cause is improper input validation (CWE-20) where the downloader fails to strip or verify setuid permissions on files contained within downloaded tar-archive Extension Packs. An attacker positioned to perform a Man-in-the-Middle (MitM) attack can intercept the unencrypted HTTP update request and provide a malicious Extension Pack containing a setuid binary. When the victim installs the update (requiring administrative interaction), the malicious binary is stored with root ownership and setuid permissions, allowing for local privilege escalation to root. This is addressed in VirtualBox versions 5.0.32 and 5.1.14.

Affected products

  • Oracle VM VirtualBox prior to 5.0.32, prior to 5.1.14

Timeline

  • 2016-12: disclosed: Vulnerability reported to Oracle by Wolfgang Hotwagner
  • 2017-01-17: patched: Oracle released a patch in the January Critical Patch Update
  • 2017-01-27: advisory: Initial public disclosure and NVD publication

References

Related threats