CVE-2018-3294

Priority
Description
Vulnerability in the Oracle VM VirtualBox component of Oracle
Virtualization (subcomponent: Core). The supported version that is affected
is Prior to 5.2.20. Easily exploitable vulnerability allows low privileged
attacker with network access via VRDP to compromise Oracle VM VirtualBox.
Successful attacks require human interaction from a person other than the
attacker and while the vulnerability is in Oracle VM VirtualBox, attacks
may significantly impact additional products. Successful attacks of this
vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base
Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
Notes
Package
Upstream:released (5.2.20-dfsg-1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needs-triage)
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):needed
Ubuntu 20.04 LTS (Focal Fossa):not-affected (6.0.8-dfsg-7)
Ubuntu 20.10 (Groovy Gorilla):not-affected (6.0.8-dfsg-7)
More Information

Updated: 2020-09-09 22:22:39 UTC (commit b67d7d8b03f173f825cd706df5bd078bca500b0e)