#VU78436 Buffer overflow in Oracle VM VirtualBox - CVE-2023-22018 

 

#VU78436 Buffer overflow in Oracle VM VirtualBox - CVE-2023-22018

Published: July 19, 2023 / Updated: July 27, 2023


Vulnerability identifier: #VU78436
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-22018
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Oracle VM VirtualBox
Software vendor:
Oracle

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation within the Core component in Oracle VM VirtualBox when handling USB request messages. A remote attacker can trigger memory corruption and execute arbitrary code on the target system in the context of the RDP service.



Remediation

Install updates from vendor's website.

External links