CVE-2017-3558
published 2017-04-24CVE-2017-3558: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and…
PriorityP348high8.5CVSS 3.0
AVLACLPRNUINSCCLILAH
EXPLOIT
EPSS
2.91%
85.5th percentile
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 5.1.20-dfsg-1 (sid) | virtualbox 5.1.20-dfsg-1 (sid) |
| oracle | vm_virtualbox | >= 5.0.0 < 5.0.38 | 5.0.38 |
| oracle | vm_virtualbox | >= 5.1.0 < 5.1.20 | 5.1.20 |
| oracle_corporation | oracle_vm_virtualbox | >= unspecified < 5.0.38 | 5.0.38 |
| oracle_corporation | oracle_vm_virtualbox | >= unspecified < 5.1.20 | 5.1.20 |
| sun | virtualbox | >= 0 < 5.1.38-dfsg-0ubuntu1.16.04.1 | 5.1.38-dfsg-0ubuntu1.16.04.1 |
CVSS provenance
nvdv3.08.5HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.5HIGH
vendor_debian8.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mj36-xjx9-9qp7: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
ghsa_unreviewed·2022-05-13
CVE-2017-3558 [HIGH] GHSA-mj36-xjx9-9qp7: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible dat
OSV
CVE-2017-3558: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
osv·2017-04-24·CVSS 8.5
CVE-2017-3558 [HIGH] CVE-2017-3558: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible dat
Debian
CVE-2017-3558: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
vendor_debian·2017·CVSS 8.5
CVE-2017-3558 [HIGH] CVE-2017-3558: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible dat
No detection rules found.
Projectzero
Thinking Outside The Box [dusted off draft from 2017]
blogs_projectzero·2025-12-16·CVSS 8.5
CVE-2017-3558 [HIGH] Thinking Outside The Box [dusted off draft from 2017]
## Preface
Hello from the future!
This is a blogpost I originally drafted in early 2017. I wrote what I intended to be the first half of this post (about escaping from the VM to the VirtualBox host userspace process with CVE-2017-3558 ), but I never got around to writing the second half ( going from the VirtualBox host userspace process to the host kernel ), and eventually sorta forgot about this old post draft⦠But it seems a bit sad to just leave this old draft rotting around forever, so I decided to put it in our blogpost queue now, 8 years after I originally drafted it. Iâve very lightly edited it now (added some links, fixed some grammar), but itâs still almost as I drafted it back then.
When you read this post, keep in mind that unless otherwise noted, it is describing the s
Projectzero
Thinking Outside The Box [dusted off draft from 2017]
blogs_projectzero·CVSS 8.5
CVE-2017-3558 [HIGH] Thinking Outside The Box [dusted off draft from 2017]
## Preface
Hello from the future!
This is a blogpost I originally drafted in early 2017. I wrote what I intended to be the first half of this post (about escaping from the VM to the VirtualBox host userspace process with CVE-2017-3558), but I never got around to writing the second half (going from the VirtualBox host userspace process to the host kernel), and eventually sorta forgot about this old post draft⦠But it seems a bit sad to just leave this old draft rotting around forever, so I decided to put it in our blogpost queue now, 8 years after I originally drafted it. Iâve very lightly edited it now (added some links, fixed some grammar), but itâs still almost as I drafted it back then.
When you read this post, keep in mind that unless otherwise noted, it is describing the situ
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97744http://www.securitytracker.com/id/1038288https://www.exploit-db.com/exploits/41904/http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97744http://www.securitytracker.com/id/1038288https://www.exploit-db.com/exploits/41904/
2017-04-24
Published