CVE-2018-2694 is a critical vulnerability in Oracle VM VirtualBox, affecting versions prior to 5.1.32 and 5.2.6. This easily exploitable flaw allows a low-privileged attacker with local logon access to the VirtualBox infrastructure to compromise the software, potentially leading to a complete takeover. With a CVSS v3.0 score of 8.8 (High), successful exploitation can result in significant impacts to confidentiality, integrity, and availability, and may affect additional products beyond VirtualBox itself. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.1.0, < 5.1.32CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 5.2.0, < 5.2.6CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.1.32CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.2.6CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.