Oracle issues patches for 10 'virtual machine escape' flaws in VirtualBox
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-5753 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local us Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. NVD description · AI analysis pending | 5.6 | 94% | PoC |
| — | |
| CVE-2018-2698 +1 in the same advisory: …2694 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). NVD description · AI analysis pending | 8.8 | 2% |
| — |
Full article555 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The "easily exploitable" vulnerabilities allow a hacker to stage a "virtual machine escape" to attack the host operating system.
Enterprise tech giant Oracle released a collection of critical security patches this month to address 10 exploitable vulnerabilities in VirtualBox.
Both popular and powerful, VirtualBox is Oracle’s hypervisor, which allows users to run virtual machines on a user’s host operating system.
Affecting anyone using VirtualBox, the “easily exploitable” vulnerabilities allow a hacker to stage a “virtual machine escape” and attack the host operating system, TechRepublic reports.
The vulnerabilities are found in the core graphics framework that is mirrored between the host and guest machine. It affects all host operating systems, according to SecuriTeam. You can find an extensive and technical write-up of the exploits here.
The vulnerability in mirrored memory allows attackers to exploit the host operating system from the virtual machine.
This particular vulnerability, CVE-2018-2698, was found by independent security researcher Niklas Baumstark via Beyond Security’s SecuriTeam.
After Oracle issued patches and an announcement, Baumstark outlined the problems on Twitter:
CVE-2018-2698 is a powerful OOB read/write primitive in the (always-on) VBVA graphics component. It can be used to escape a VBox VM and escalate privs to SYSTEM on Windows 10 hosts. Since the patch is public now, definitely upgrade if you are running malicious code inside a VM. pic.twitter.com/2s4IWuNq3e
— Niklas B (@_niklasb) January 17, 2018
Oracle fixed some of my VBox bugs 🙂 CVE-2018-2694 was the macOS privilege escalation. strcpy into a fixed-size heap buffer… It's interesting this is even exploitable, my approach was to spray memory inside the guest which ends up at predictable addresses in the host process. pic.twitter.com/0A5doVXYnR
— Niklas B (@_niklasb) January 17, 2018
Oracle has a full list of vulnerabilities addressed by the January patches including patches addressing the Spectre (CVE-2017-5753, CVE-2017-5715) and Meltdown (CVE-2017-5754) Intel processor vulnerabilities. Oracle is monitoring the performance impact of the patches in much the same way that other major vendors, including Amazon and Microsoft, are doing.
Oracle urges all VirtualBox users to apply the latest patches.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/virtualbox-virtual-machine-escape-oracle/