The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.
References
Configurations
History
21 Nov 2024, 00:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/31361 - Broken Link, Vendor Advisory | |
References | () http://securityreason.com/securityalert/4107 - Broken Link | |
References | () http://securitytracker.com/id?1020625 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://sunsolve.sun.com/search/document.do?assetkey=1-66-240095-1 - Broken Link | |
References | () http://virtualbox.org/wiki/Changelog - Product | |
References | () http://www.coresecurity.com/content/virtualbox-privilege-escalation-vulnerability - Exploit, Third Party Advisory | |
References | () http://www.securityfocus.com/archive/1/495095/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/30481 - Broken Link, Exploit, Third Party Advisory, VDB Entry | |
References | () http://www.vupen.com/english/advisories/2008/2293 - Broken Link | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/44202 - Third Party Advisory, VDB Entry | |
References | () https://www.exploit-db.com/exploits/6218 - Exploit, Third Party Advisory, VDB Entry |
16 Jul 2024, 17:23
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:sun:xvm_virtualbox:1.4.0:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:1.3.6:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:1.5.0:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:*:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:1.3.4:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:1.5.4:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:1.3.8:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:1.3.2:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:1.6.0:*:*:*:*:*:*:* cpe:2.3:a:sun:xvm_virtualbox:1.5.6:*:*:*:*:*:*:* |
cpe:2.3:a:oracle:virtualbox:*:*:*:*:*:*:*:* |
CVSS |
v2 : v3 : |
v2 : 7.2
v3 : 8.8 |
First Time |
Oracle
Oracle virtualbox |
|
References | () http://secunia.com/advisories/31361 - Broken Link, Vendor Advisory | |
References | () http://securityreason.com/securityalert/4107 - Broken Link | |
References | () http://securitytracker.com/id?1020625 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://sunsolve.sun.com/search/document.do?assetkey=1-66-240095-1 - Broken Link | |
References | () http://virtualbox.org/wiki/Changelog - Product | |
References | () http://www.coresecurity.com/content/virtualbox-privilege-escalation-vulnerability - Exploit, Third Party Advisory | |
References | () http://www.securityfocus.com/archive/1/495095/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/30481 - Broken Link, Exploit, Third Party Advisory, VDB Entry | |
References | () http://www.vupen.com/english/advisories/2008/2293 - Broken Link | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/44202 - Third Party Advisory, VDB Entry | |
References | () https://www.exploit-db.com/exploits/6218 - Exploit, Third Party Advisory, VDB Entry |
Information
Published : 2008-08-05 19:41
Updated : 2025-03-14 19:06
NVD link : CVE-2008-3431
Mitre link : CVE-2008-3431
CVE.ORG link : CVE-2008-3431
JSON object : View
Products Affected
oracle
- virtualbox
CWE