CVE-2023-22100 is a high-severity vulnerability affecting Oracle VM VirtualBox versions prior to 7.0.12, specifically within the 7.0.x platform. A highly privileged attacker with logon access to the VirtualBox infrastructure can exploit this vulnerability to gain unauthorized access to critical data or all VirtualBox-accessible data, and cause a complete denial of service. While the CVSS 3.1 Base Score is 7.9, indicating significant confidentiality and availability impacts, there is currently no public exploit code, Metasploit modules, or community discussion regarding active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.0.12CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* | ||
< 7.0.12CPE match | cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.