[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-3431Date: (C)2008-08-05   (M)2023-12-22


The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the .VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1020625
http://www.securityfocus.com/archive/1/495095/100/0/threaded
SUNALERT-240095
BID-30481
SECUNIA-31361
SREASON-4107
EXPLOIT-DB-6218
ADV-2008-2293
http://virtualbox.org/wiki/Changelog
http://www.coresecurity.com/content/virtualbox-privilege-escalation-vulnerability
sun-xvmvirtualbox-privilege-escalation(44202)

CWE    1
CWE-264
OVAL    1
oval:org.secpod.oval:def:38566

© SecPod Technologies