First published: Thu Oct 17 2024(Updated: )
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2024-21273.
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle VM VirtualBox |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-24-1414 has a high severity rating due to the risk of local attackers disclosing sensitive information.
To fix ZDI-24-1414, users should ensure they are running the latest version of Oracle VirtualBox with the necessary security patches applied.
ZDI-24-1414 affects installations of Oracle VirtualBox where an attacker can execute high-privileged code on the guest system.
ZDI-24-1414 enables local attackers to disclose sensitive information from the affected Oracle VirtualBox installations.
No, remote access is not required to exploit ZDI-24-1414; the attacker must have local access to execute high-privileged code.