CVE-2020-14713 is a high-severity vulnerability in Oracle VM VirtualBox, affecting versions prior to 5.2.44, 6.0.24, and 6.1.12. A highly privileged attacker with logon access to the infrastructure can exploit this vulnerability to fully compromise Oracle VM VirtualBox, potentially impacting additional products. Despite its high CVSS score of 7.5, indicating significant confidentiality, integrity, and availability impacts, there is no known public exploit code, Metasploit modules, or Nuclei templates available. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.44CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.24CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 6.1.0, < 6.1.12CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
15.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.