peter bassill · operator
$ cve CVE-2008-3431 JSON

CVE-2008-3431 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 6.9% (pctl 94)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS6.88% — more likely to be exploited than 94% of all CVEs
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2008-08-05
Last modified2026-06-16

CISA KEV

NameOracle VirtualBox Insufficient Input Validation Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productOracle / VirtualBox
Ransomware usenone reported

Affected (1)

VendorProduct
oraclevirtualbox

Public exploits

SourceTitleDate
exploit-dbSun xVM VirtualBox < 1.6.4 - Privilege Escalation (PoC)2008-08-10

References

→ the Explorer  ·  watch your stack  ·  NVD