CVE-2014-2489: Medium severity oracle virtualbox vulnerability
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2489?
CVE-2014-2489 is classified as a high severity vulnerability, impacting confidentiality, integrity, and availability.
How do I fix CVE-2014-2489?
To fix CVE-2014-2489, upgrade Oracle VM VirtualBox to version 3.2.24 or later, or to version 4.0.26, 4.1.34, 4.2.26, or 4.3.12.
Which versions of Oracle VM VirtualBox are affected by CVE-2014-2489?
Oracle VM VirtualBox versions before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 are affected by CVE-2014-2489.
Can CVE-2014-2489 be exploited locally?
Yes, CVE-2014-2489 allows local users to exploit the vulnerability through unknown vectors.
What types of issues can CVE-2014-2489 cause?
CVE-2014-2489 can affect confidentiality, integrity, and availability of the virtual machine environment.