#VU78436 Buffer overflow in Oracle VM VirtualBox - CVE-2023-22018
Published: July 19, 2023 / Updated: July 27, 2023
Vulnerability identifier: #VU78436
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-22018
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Oracle VM VirtualBox
Oracle VM VirtualBox
Software vendor:
Oracle
Oracle
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation within the Core component in Oracle VM VirtualBox when handling USB request messages. A remote attacker can trigger memory corruption and execute arbitrary code on the target system in the context of the RDP service.
Remediation
Install updates from vendor's website.