Use of Uninitialized Variable in Oracle VM VirtualBox - CVE-2020-2575

 

Use of Uninitialized Variable in Oracle VM VirtualBox - CVE-2020-2575

Published: May 4, 2020


Vulnerability identifier: #VU27493
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2575
CWE-ID: CWE-457
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerabilities allows a local user to escalate privileges on the target system.

The vulnerability exists within the processing of data sent to OHCI endpoints due to the lack of proper initialization of memory prior to accessing it. A local user can gain elevated privileges on the target system and execute arbitrary code.


Affected software

Oracle VM VirtualBox

How to mitigate CVE-2020-2575

Install updates from vendor's website.

Oracle VM VirtualBox - addressed in versions 5.2.40, 6.0.20, 6.1.6

External References

Related Security Bulletins