Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-0602
HistoryJan 21, 2016 - 12:00 a.m.

CVE-2016-0602

2016-01-2100:00:00
ubuntu.com
ubuntu.com
13

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

EPSS

0.012

Percentile

85.5%

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle
Virtualization VirtualBox before 5.0.14 allows local users to affect
confidentiality, integrity, and availability via unknown vectors related to
Windows Installer. NOTE: the previous information is from the January 2016
CPU. Oracle has not commented on third-party claims that this is an
untrusted search path issue that allows local users to gain privileges via
a Trojan horse dll in the “application directory.”

Notes

Author Note
sbeattie windows installer, 5.0.x only
OSVersionArchitecturePackageVersionFilename
ubuntu15.10noarchvirtualbox< 5.0.14-dfsg-0ubuntu1.15.10.1UNKNOWN

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

EPSS

0.012

Percentile

85.5%