PT-2025-4255 · Oracle+2 · Virtualbox+2
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle VM VirtualBox versions prior to 7.0.24
Oracle VM VirtualBox versions prior to 7.1.6
Description
A flaw in the Core component of Oracle VM VirtualBox involves authorization mechanism deficiencies and a speculative store bypass. This allows a low-privileged local attacker with access to the infrastructure where the software executes to compromise the system. Exploitation can be achieved via cache-based side-channel attacks, potentially resulting in unauthorized access to critical data or complete access to all data accessible by Oracle VM VirtualBox.
Recommendations
Update to version 7.0.24 or later.
Update to version 7.1.6 or later.
Fix
DoS
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Virtualbox
Red Os