Buffer overflow in Oracle VM VirtualBox - CVE-2023-22018

 

Buffer overflow in Oracle VM VirtualBox - CVE-2023-22018

Published: July 19, 2023 / Updated: July 27, 2023


Vulnerability identifier: #VU78436
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22018
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation within the Core component in Oracle VM VirtualBox when handling USB request messages. A remote attacker can trigger memory corruption and execute arbitrary code on the target system in the context of the RDP service.



Affected software

Oracle VM VirtualBox

How to mitigate CVE-2023-22018

Install updates from vendor's website.

Oracle VM VirtualBox - addressed in versions 6.1.46, 7.0.10

External References

Related Security Bulletins