Executive brief
A vulnerability in Oracle VM VirtualBox's graphics emulation component allows a user with low-level access to the system to compromise the virtualization software. This could lead to the unauthorized modification or deletion of critical data and can be used to crash the system, causing a total service outage. Because the flaw affects the virtualization layer, an attack could potentially impact other virtual machines or the underlying host infrastructure.
Technical details
This vulnerability exists in the VirtualBox SVGA Emulation subcomponent of Oracle VM VirtualBox. It is classified as an 'easily exploitable' flaw that requires a low-privileged attacker to have local logon access to the infrastructure where VirtualBox is executing. While specific technical root causes (like buffer overflow or logic error) are not detailed in the advisory, the exploit results in a 'Changed Scope' (S:C), meaning an attacker can impact components beyond the immediate security scope of the virtual machine. Successful exploitation can lead to unauthorized creation, deletion, or modification of all accessible data and the ability to cause a repeatable crash (DoS). The issue is resolved in VirtualBox versions 5.0.32 and 5.1.14.
Affected products
- Oracle VM VirtualBox prior to 5.0.32, prior to 5.1.14
Timeline
- 2017-01-27: advisory: Initial disclosure by Oracle
- 2017-02-14: other: Gentoo Linux security advisory released