Vulnerability Name: CVE-2014-2487 (CCN-94611) Assigned: 2014-07-15 Published: 2014-07-15 Updated: 2018-12-13 Summary: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-4261 . Per: http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html "Applies only when VirtualBox is running on a Windows host operating system." CVSS v3 Severity: 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C )5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
6.9 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C )5.1 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2014-2487 Source: FULLDISC Type: Mailing List, Third Party Advisory20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities Source: CCN Type: Oracle Critical Patch Update Advisory - July 2014Oracle Critical Patch Update Advisory - July 2014 Source: CONFIRM Type: Vendor Advisoryhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html Source: BUGTRAQ Type: Third Party Advisory, VDB Entry20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities Source: CCN Type: BID-68584Oracle VM VirtualBox CVE-2014-2487 Local Security Vulnerability Source: CONFIRM Type: Third Party Advisoryhttp://www.vmware.com/security/advisories/VMSA-2014-0012.html Source: XF Type: UNKNOWNoracle-cpujul2014-cve20142487(94611) Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2014-2487 Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* (Version >= 3.2.0 and < 3.2.24)OR cpe:/a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* (Version >= 4.0 and < 4.0.26) OR cpe:/a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* (Version >= 4.1.0 and < 4.1.34) OR cpe:/a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* (Version >= 4.2.0 and < 4.2.26) OR cpe:/a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* (Version >= 4.3.0 and < 4.3.14) AND cpe:/o:microsoft:windows:*:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/o:microsoft:windows:-:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.0:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.6:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.8:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.10:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.12:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.14:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.16:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.4:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.16:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.0:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.10:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.12:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.14:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.4:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.6:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.8:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.26:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.24:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.10:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.12:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.14:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.16:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.18:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.2:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.20:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.22:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.4:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.6:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.8:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.18:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.10:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.12:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.14:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.16:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.6:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.8:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.18:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.18:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.20:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.3.2:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.3.4:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.20:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.28:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.3.6:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.0.22:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.1.30:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:3.2.20:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.3.8:*:*:*:*:*:*:* OR cpe:/a:oracle:vm_virtualbox:4.2.22:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
oracle vm virtualbox *
oracle vm virtualbox *
oracle vm virtualbox *
oracle vm virtualbox *
oracle vm virtualbox *
microsoft windows *
microsoft windows -
oracle vm virtualbox 3.2
oracle vm virtualbox 4.0
oracle vm virtualbox 4.1.0
oracle vm virtualbox 4.2.0
oracle vm virtualbox 4.2.6
oracle vm virtualbox 4.2.8
oracle vm virtualbox 4.2.10
oracle vm virtualbox 4.2.12
oracle vm virtualbox 4.2.14
oracle vm virtualbox 4.2.16
oracle vm virtualbox 4.2.2
oracle vm virtualbox 4.2.4
oracle vm virtualbox 3.2.16
oracle vm virtualbox 3.2.0
oracle vm virtualbox 3.2.10
oracle vm virtualbox 3.2.12
oracle vm virtualbox 3.2.14
oracle vm virtualbox 3.2.2
oracle vm virtualbox 3.2.4
oracle vm virtualbox 3.2.6
oracle vm virtualbox 3.2.8
oracle vm virtualbox 4.1.26
oracle vm virtualbox 4.1.24
oracle vm virtualbox 4.1.10
oracle vm virtualbox 4.1.12
oracle vm virtualbox 4.1.14
oracle vm virtualbox 4.1.16
oracle vm virtualbox 4.1.18
oracle vm virtualbox 4.1.2
oracle vm virtualbox 4.1.20
oracle vm virtualbox 4.1.22
oracle vm virtualbox 4.1.4
oracle vm virtualbox 4.1.6
oracle vm virtualbox 4.1.8
oracle vm virtualbox 4.0.18
oracle vm virtualbox 4.0.0
oracle vm virtualbox 4.0.10
oracle vm virtualbox 4.0.12
oracle vm virtualbox 4.0.14
oracle vm virtualbox 4.0.16
oracle vm virtualbox 4.0.2
oracle vm virtualbox 4.0.4
oracle vm virtualbox 4.0.6
oracle vm virtualbox 4.0.8
oracle vm virtualbox 3.2.18
oracle vm virtualbox 4.2.18
oracle vm virtualbox 4.2.20
oracle vm virtualbox 4.3.0
oracle vm virtualbox 4.3.2
oracle vm virtualbox 4.3.4
oracle vm virtualbox 4.0.20
oracle vm virtualbox 4.1.28
oracle vm virtualbox 4.3.6
oracle vm virtualbox 4.0.22
oracle vm virtualbox 4.1.30
oracle vm virtualbox 3.2.20
oracle vm virtualbox 4.3.8
oracle vm virtualbox 4.2.22