CVE-2021-2264 is a high-severity vulnerability (CVSS 8.4) affecting Oracle VM VirtualBox versions prior to 6.1.20, specifically within its Core component. A low-privileged attacker with local logon access to the VirtualBox infrastructure can exploit this vulnerability to gain unauthorized creation, deletion, or modification access to critical data, or complete access to all VirtualBox accessible data. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it is not listed on the CISA KEV catalog, the potential for significant data compromise warrants attention. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.20CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.