Junglewise Threat Intelligence

CVE-2008-3431: Oracle VirtualBox Insufficient Input Validation Vulnerability

CVE-2008-3431 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Technologies: Oracle VirtualBox. Vendors: Oracle, Sun.

Executive brief

The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox uses the METHOD_NEITHER communication method for IOCTLs without properly validating buffers. Local attackers can exploit this by sending crafted kernel addresses via DeviceIoControl to the VBoxDrv device to execute arbitrary code with elevated privileges.

Affected products

  • Sun xVM VirtualBox before 1.6.4
  • Oracle VirtualBox before 1.6.4

Timeline

  • 2008-08-04: disclosed: Initial disclosure date based on external references (e.g., BID 30481)
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats