CVE-2019-2509 is a denial-of-service vulnerability affecting Oracle VM VirtualBox versions prior to 5.2.24 and 6.0.2. A low-privileged attacker with logon access to the VirtualBox infrastructure can easily exploit this flaw to cause a complete system crash or frequent hangs. The CVSS 3.0 Base Score is 6.5 (Medium), indicating a local attack vector with low complexity and a high impact on availability. There is no known exploit code publicly available (Metasploit, Nuclei, ExploitDB), and the vulnerability shows no signs of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.24CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:6.0.0:*:*:*:*:*:*:* | ||
< 6.0.2CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.