CVE-2018-2835
published 2018-04-19CVE-2018-2835: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and…
PriorityP336high8.2CVSS 3.0
AVLACLPRLUIRSCCHIHAH
EPSS
0.53%
41.6th percentile
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 5.2.10-dfsg-1 (sid) | virtualbox 5.2.10-dfsg-1 (sid) |
| oracle | vm_virtualbox | >= 5.1.0 < 5.1.36 | 5.1.36 |
| oracle | vm_virtualbox | >= 5.2.0 < 5.2.10 | 5.2.10 |
| oracle_corporation | vm_virtualbox | >= unspecified < 5.1.36 | 5.1.36 |
| oracle_corporation | vm_virtualbox | >= unspecified < 5.2.10 | 5.2.10 |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv8.2HIGH
vendor_debian8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-2835: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
vendor_debian·2018·CVSS 8.2
CVE-2018-2835 [HIGH] CVE-2018-2835: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
Scope: local
sid: resolved (fixe
GHSA
GHSA-8wfm-7f7g-w7p4: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
ghsa_unreviewed·2022-05-13
CVE-2018-2835 [HIGH] GHSA-8wfm-7f7g-w7p4: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
OSV
CVE-2018-2835: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
osv·2018-04-19·CVSS 8.2
CVE-2018-2835 [HIGH] CVE-2018-2835: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
No detection rules found.
No public exploits indexed.
Trendmicro
VirtualBox 3D Acceleration: An accelerated attack surface
blogs_trendmicro·2018-08-29·CVSS 8.2
[HIGH] VirtualBox 3D Acceleration: An accelerated attack surface
## VirtualBox 3D Acceleration: An accelerated attack surface
This post goes over VirtualBox 3D Acceleration, which is an accelerated attack surface.
By: Zero Day Initiative 2018/08/29 Read time: ( words)
Save to Folio
VirtualBox is a free hypervisor currently being developed and maintained by Oracle Corporation. While perhaps lesser known, it’s a direct competitor to VMware WorkStation and Microsoft Hyper-V. In July 2017, we started receiving vulnerabilities in VirtualBox 3D acceleration functionality, which is implemented with the Chromium library . Oracle warns in their documentation against enabling 3D Acceleration due to the security implications it imposes and the attack surface it exposes. What few know is that the code behind 3D Acceleration is very old. And by old, I mean it al
Trendmicro
VirtualBox 3D Acceleration: An accelerated attack surface
blogs_trendmicro·2018-08-29·CVSS 8.2
[HIGH] VirtualBox 3D Acceleration: An accelerated attack surface
## VirtualBox 3D Acceleration: An accelerated attack surface
This post goes over VirtualBox 3D Acceleration, which is an accelerated attack surface.
By: Zero Day Initiative Aug 29, 2018 Read time: ( words)
Save to Folio
VirtualBox is a free hypervisor currently being developed and maintained by Oracle Corporation. While perhaps lesser known, it’s a direct competitor to VMware WorkStation and Microsoft Hyper-V. In July 2017, we started receiving vulnerabilities in VirtualBox 3D acceleration functionality, which is implemented with the Chromium library . Oracle warns in their documentation against enabling 3D Acceleration due to the security implications it imposes and the attack surface it exposes. What few know is that the code behind 3D Acceleration is very old. And by old, I mean it
Trendmicro
VirtualBox 3D Acceleration: An accelerated attack surface
blogs_trendmicro·2018-08-29·CVSS 8.2
[HIGH] VirtualBox 3D Acceleration: An accelerated attack surface
# VirtualBox 3D Acceleration: An accelerated attack surface
This post goes over VirtualBox 3D Acceleration, which is an accelerated attack surface.
By: Zero Day Initiative
2018/08/29
Read time: ( words)
Save to Folio
VirtualBox is a free hypervisor currently being developed and maintained by Oracle Corporation. While perhaps lesser known, it’s a direct competitor to VMware WorkStation and Microsoft Hyper-V. In July 2017, we started receiving vulnerabilities in VirtualBox 3D acceleration functionality, which is implemented with the Chromium library. Oracle warns in their documentation against enabling 3D Acceleration due to the security implications it imposes and the attack surface it exposes. What few know is that the code behind 3D Acceleration is very old. And by old, I mean it alm
Trendmicro
VirtualBox 3D Acceleration: An accelerated attack surface
blogs_trendmicro·2018-08-29·CVSS 8.2
[HIGH] VirtualBox 3D Acceleration: An accelerated attack surface
## VirtualBox 3D Acceleration: An accelerated attack surface
This post goes over VirtualBox 3D Acceleration, which is an accelerated attack surface.
By: Zero Day Initiative Aug 29, 2018 Read time: ( words)
Save to Folio
VirtualBox is a free hypervisor currently being developed and maintained by Oracle Corporation. While perhaps lesser known, it’s a direct competitor to VMware WorkStation and Microsoft Hyper-V. In July 2017, we started receiving vulnerabilities in VirtualBox 3D acceleration functionality, which is implemented with the Chromium library . Oracle warns in their documentation against enabling 3D Acceleration due to the security implications it imposes and the attack surface it exposes. What few know is that the code behind 3D Acceleration is very old. And by old, I mean it
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103857http://www.securitytracker.com/id/1040707https://security.gentoo.org/glsa/201805-08http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103857http://www.securitytracker.com/id/1040707https://security.gentoo.org/glsa/201805-08
2018-04-19
Published