CVE-2022-21571
Summary
| CVE | CVE-2022-21571 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-19 22:15:00 UTC |
| Updated | 2022-10-31 15:09:00 UTC |
| Description | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.36. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Vm Virtualbox | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - July 2022 | MISC | www.oracle.com | |
| Oracle VirtualBox: Multiple Vulnerabilities (GLSA 202208-36) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376736 Oracle Managed Virtualization (VM) VirtualBox Multiple Vulnerabilities (CPUJUL2022)
- 502497 Alpine Linux Security Update for virtualbox-guest-additions
- 690901 Free Berkeley Software Distribution (FreeBSD) Security Update for virtualbox (e1387e95-08d0-11ed-be26-001999f8d30b)
- 710611 Gentoo Linux Oracle VirtualBox Multiple Vulnerabilities (GLSA 202208-36)
- 752394 OpenSUSE Security Update for virtualbox (openSUSE-SU-2022:10067-1)
- 752597 OpenSUSE Security Update for virtualbox (openSUSE-SU-2022:10122-1)
- 752606 OpenSUSE Security Update for virtualbox (openSUSE-SU-2022:10129-1)
- 752682 OpenSUSE Security Update for virtualbox (openSUSE-SU-2022:10152-1)