CVE-2017-3316PoC(oracle / vm_virtualbox)

LOWCVSS 8.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for oracle vm_virtualbox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox prior to 5.0.32 and prior to 5.1.14. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS v3.0 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm_virtualbox

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
vm_virtualbox

2 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-15: 1Exploit Tool / Code · 2026-05-15: 1Technical Details · 2026-05-15: 105-15
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Israel@f1tym1
    PoC

    CVE-2017-3316 | Oracle VM VirtualBox up to 5.0.31/5.1.13 GUI input validation (EDB-41196 / Nessus ID 96609) https://ift.tt/hWaHROv A vulnerability identified as critical has been detected in Oracle VM VirtualBox up to 5.0.31/5.1.13. Affected is an unknown function of the compo…

    Post summary

    Oracle VM VirtualBox versions 5.0.31/5.1.13 contain a critical GUI input validation flaw (CVE‑2017‑3316), with a linked PoC available (EDB‑41196), but no active exploitation or patch information is reported.

    0000048
    974 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclevm_virtualbox5.0.30--
Apporaclevm_virtualbox5.1.12--

Explore more