CVE-2016-0602 describes an unspecified vulnerability within the Oracle VM VirtualBox component, affecting versions prior to 5.0.14. This flaw allows local users to compromise confidentiality, integrity, and availability, potentially through an untrusted search path issue involving a Trojan horse DLL during Windows Installer operations. With a CVSS score of 6.2, it has a local attack vector and high attack complexity, leading to complete compromise of all three security pillars. While Oracle has not confirmed third-party claims, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one article mentioning a related Java installer vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0.12CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.