ZDI-26-097: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-21983.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-097?
The severity of ZDI-26-097 is categorized as high due to its potential for local privilege escalation.
How do I fix ZDI-26-097?
To fix ZDI-26-097, update your Oracle VirtualBox installation to the latest version provided by Oracle.
What types of systems are affected by ZDI-26-097?
ZDI-26-097 affects installations of Oracle VirtualBox versions that are vulnerable to the heap-based buffer overflow.
Who can exploit ZDI-26-097?
ZDI-26-097 can be exploited by local attackers who have the ability to execute high-privileged code on the guest operating system.
What are the potential impacts of ZDI-26-097?
The potential impacts of ZDI-26-097 include unauthorized privilege escalation, allowing attackers to gain higher access levels on the affected system.