Executive brief
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox uses the METHOD_NEITHER communication method for IOCTLs without properly validating buffers. Local attackers can exploit this by sending crafted kernel addresses via DeviceIoControl to the VBoxDrv device to execute arbitrary code with elevated privileges.
Affected products
- Sun xVM VirtualBox before 1.6.4
- Oracle VirtualBox before 1.6.4
Timeline
- 2008-08-04: disclosed: Initial disclosure date based on external references (e.g., BID 30481)
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog