CVE-2023-21998 is a medium-severity vulnerability affecting Oracle VM VirtualBox versions prior to 6.1.44 and 7.0.8, specifically impacting Windows VMs. A high-privileged attacker with logon access to the VirtualBox infrastructure can exploit this to gain unauthorized read, insert, update, or delete access to a subset of VirtualBox data, with potential scope changes affecting other products. The CVSS 3.1 score is 4.6, indicating low confidentiality and integrity impacts. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows no active exploitation, KEV listing, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.44CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.8CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 7.0.8CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.