CVE-2019-2552 is a critical vulnerability in Oracle VM VirtualBox, affecting versions prior to 5.2.24 and 6.0.2. This flaw allows a low-privileged attacker with local logon access to the VirtualBox infrastructure to fully compromise the virtualization software. With a CVSS 3.0 score of 8.8 (High), this easily exploitable vulnerability has significant impacts on confidentiality, integrity, and availability, potentially leading to a complete takeover of VirtualBox. The attack vector is local, requiring minimal privileges and no user interaction. Despite its high severity, there is currently no evidence of active exploitation, nor are public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.24CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:6.0.0:*:*:*:*:*:*:* | ||
< 6.0.2CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.