CVE-2008-3431
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Oracle VirtualBox Insufficient Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 7% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
oracle: virtualbox
קישורים
- http://secunia.com/advisories/31361 Broken LinkVendor Advisory
- http://secunia.com/advisories/31361 Broken LinkVendor Advisory
- http://www.coresecurity.com/content/virtualbox-privilege-escalation-vulnerabil… ExploitThird Party Advisory
- http://www.securityfocus.com/bid/30481 Broken LinkExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/6218 ExploitThird Party AdvisoryVDB Entry
- http://www.coresecurity.com/content/virtualbox-privilege-escalation-vulnerabil… ExploitThird Party Advisory
- http://www.securityfocus.com/bid/30481 Broken LinkExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/6218 ExploitThird Party AdvisoryVDB Entry
- http://securityreason.com/securityalert/4107 Broken Link
- http://securitytracker.com/id?1020625 Broken LinkThird Party AdvisoryVDB Entry