CVE-2018-2844 is a critical vulnerability in Oracle VM VirtualBox, specifically affecting versions prior to 5.1.36 and 5.2.10. This easily exploitable flaw allows a low-privileged attacker with logon access to the host infrastructure to compromise the VirtualBox component. With a CVSS 3.0 Base Score of 8.8 (High), successful exploitation can lead to a complete takeover of Oracle VM VirtualBox, impacting confidentiality, integrity, and availability, and potentially affecting additional products due to its scope. While the vulnerability is not listed in CISA's KEV catalog and there are no known public exploits in Metasploit, Nuclei, or ExploitDB, there has been some community discussion, including a Reddit post detailing a VM escape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.1.0, < 5.1.36CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 5.2.0, < 5.2.10CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.1.36CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.2.10CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.