CVE-2020-2701 is a high-severity vulnerability affecting Oracle VM VirtualBox versions prior to 5.2.36, 6.0.16, and 6.1.2. A highly privileged attacker with logon access to the VirtualBox infrastructure can exploit this vulnerability, potentially leading to a complete takeover of the VirtualBox instance and significant impact on other products. Despite its high CVSS score of 7.5, indicating high confidentiality, integrity, and availability impacts, the vulnerability is difficult to exploit. There is currently no public exploit intelligence, such as Metasploit or ExploitDB modules, and it has received minimal community discussion or media coverage, suggesting it is not actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.2.0, < 5.2.36CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.16CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 6.1.0, < 6.1.2CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 5.2.36CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 6.0.16CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.