CVE-2017-10129 is a critical vulnerability in Oracle VM VirtualBox versions prior to 5.1.24, specifically affecting its Core subcomponent. This easily exploitable flaw allows a low-privileged attacker with logon access to the infrastructure where VirtualBox runs to achieve a complete takeover of the VirtualBox instance, potentially impacting additional products. With a CVSS 3.0 score of 8.8 (High), it poses significant risks to confidentiality, integrity, and availability. While not actively exploited in the wild according to KEV, an ExploitDB entry (EDB-42426) exists, indicating public exploit code for privilege escalation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1.22CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.1.24CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.