Use of Uninitialized Variable in Oracle VM VirtualBox - CVE-2020-2575
Published: May 4, 2020
Vulnerability identifier: #VU27493
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2575
CWE-ID: CWE-457
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerabilities allows a local user to escalate privileges on the target system.
The vulnerability exists within the processing of data sent to OHCI endpoints due to the lack of proper initialization of memory prior to accessing it. A local user can gain elevated privileges on the target system and execute arbitrary code.
Affected software
Oracle VM VirtualBox
How to mitigate CVE-2020-2575
Install updates from vendor's website.
Oracle VM VirtualBox - addressed in versions 5.2.40, 6.0.20, 6.1.6