CVE-2017-3563 is a critical vulnerability in Oracle VM VirtualBox, affecting versions prior to 5.0.38 and 5.1.20. It allows a low-privileged attacker with logon access to the VirtualBox infrastructure to achieve a complete takeover of the VirtualBox component. Rated with a CVSS 3.0 Base Score of 8.8 (High), this vulnerability has a low attack complexity and does not require user interaction, leading to high impacts on confidentiality, integrity, and availability. The attack vector is local, meaning an attacker needs local access to the system. While not listed on the KEV catalog, an exploit (EDB-41908) for privilege escalation on Windows has been published on ExploitDB. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.0.38CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 5.1.0, < 5.1.20CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.0.38CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.1.20CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.