CVE-2017-10392 is a high-privileged vulnerability in Oracle VM VirtualBox (versions prior to 5.1.30) that allows an authenticated attacker with logon access to the infrastructure to compromise the virtualization software. Successful exploitation can lead to a complete denial of service, unauthorized data modification, and limited unauthorized data disclosure. With a CVSS 3.0 Base Score of 7.3 (High), this vulnerability requires high privileges and local access but has a significant impact on confidentiality, integrity, and availability. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.1.28CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:5.1.28:*:*:*:*:*:*:* | ||
< 5.1.30CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.