CVE-2008-3431: Oracle VirtualBox Insufficient Input Validation Vulnerability
An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.
Other sources
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHODNEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3431?
CVE-2008-3431 is classified as a critical severity vulnerability due to its potential for local arbitrary code execution.
How do I fix CVE-2008-3431?
To remediate CVE-2008-3431, upgrade Sun xVM VirtualBox to version 1.6.4 or later.
What versions of Sun xVM VirtualBox are affected by CVE-2008-3431?
CVE-2008-3431 affects Sun xVM VirtualBox versions up to and including 1.6.2, along with specified earlier versions.
What type of vulnerability is CVE-2008-3431?
CVE-2008-3431 is an input validation vulnerability that can lead to local execution of arbitrary code.
Is CVE-2008-3431 a zero-day vulnerability?
No, CVE-2008-3431 is not classified as a zero-day vulnerability since it has already been identified and addressed.