CVE-2017-3576 is a critical vulnerability in Oracle VM VirtualBox, affecting versions prior to 5.0.38 and 5.1.20, specifically within its Core subcomponent. This easily exploitable flaw allows a low-privileged attacker with logon access to the VirtualBox infrastructure to compromise the virtualization software, potentially leading to a complete takeover and significant impact on additional products. With a CVSS 3.0 Base Score of 8.8 (High), it poses serious risks to confidentiality, integrity, and availability. While not listed on the KEV catalog, an ExploitDB entry (EDB-41907) details a privilege escalation exploit for VirtualBox 5.1.14, indicating public exploit code availability. Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.0.38CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 5.1.0, < 5.1.20CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.0.38CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.1.20CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.