CVE-2017-3575
published 2017-04-24CVE-2017-3575: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and…
PriorityP337high7.9CVSS 3.0
AVLACLPRHUINSCCNIHAH
EXPLOIT
EPSS
1.44%
70.2th percentile
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 5.1.20-dfsg-1 (sid) | virtualbox 5.1.20-dfsg-1 (sid) |
| oracle | vm_virtualbox | >= 5.0.0 < 5.0.38 | 5.0.38 |
| oracle | vm_virtualbox | >= 5.1.0 < 5.1.20 | 5.1.20 |
| oracle_corporation | oracle_vm_virtualbox | >= unspecified < 5.0.38 | 5.0.38 |
| oracle_corporation | oracle_vm_virtualbox | >= unspecified < 5.1.20 | 5.1.20 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.40 | 2.0.0+dfsg-2ubuntu1.40 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.24 | 1:2.5+dfsg-5ubuntu10.24 |
| sun | virtualbox | >= 0 < 5.1.38-dfsg-0ubuntu1.16.04.1 | 5.1.38-dfsg-0ubuntu1.16.04.1 |
CVSS provenance
nvdv3.07.9HIGHCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.9HIGH
vendor_debian7.9HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g8qf-8h4h-jwfr: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
ghsa_unreviewed·2022-05-13
CVE-2017-3575 [HIGH] GHSA-g8qf-8h4h-jwfr: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.9 (Integrity and Availability impacts).
OSV
qemu regression
osv·2018-03-05·CVSS 4.4
CVE-2017-11334 qemu regression
qemu regression
USN-3575-1 fixed vulnerabilities in QEMU. The fix for CVE-2017-11334 caused
a regression in Xen environments. This update removes the problematic fix
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that QEMU incorrectly handled guest ram. A privileged
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2017-11334)
David Buchanan discovered that QEMU incorrectly handled the VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 17.10. (CVE-2017-13672)
Thomas Garnier discove
OSV
CVE-2017-3575: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
osv·2017-04-24·CVSS 7.9
CVE-2017-3575 [HIGH] CVE-2017-3575: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.9 (Integrity and Availability impacts).
Debian
CVE-2017-3575: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
vendor_debian·2017·CVSS 7.9
CVE-2017-3575 [HIGH] CVE-2017-3575: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.9 (Integrity and Availability impacts).
No detection rules found.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97755http://www.securitytracker.com/id/1038288https://www.exploit-db.com/exploits/41906/http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97755http://www.securitytracker.com/id/1038288https://www.exploit-db.com/exploits/41906/
2017-04-24
Published