CVE-2021-25319Incorrect Default Permissions in Factory

Severity
7.8HIGHNVD
EPSS
0.0%
top 93.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 5
Latest updateMay 24

Description

A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5opensuse/factoryvirtualbox6.1.20-1.1
NVDopensuse/factory6.1.20-1.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x9mv-6frm-qg9c: A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to esc2022-05-24
CVEList
virtualbox: missing sticky bit for /etc/vbox allows local root exploit for members of vboxusers group2021-05-05
OSV
CVE-2021-25319: A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to esc2021-05-05

📋Vendor Advisories

1
Debian
CVE-2021-25319: virtualbox - A Incorrect Default Permissions vulnerability in the packaging of virtualbox of ...2021
CVE-2021-25319 — Incorrect Default Permissions | cvebase